Out-of-Bounds Write Vulnerability in Dovecot ManageSieve Service
CVE-2026-40013

4.3MEDIUM

What is CVE-2026-40013?

An authenticated attacker can exploit a vulnerability in the Dovecot ManageSieve service by submitting a specially crafted Sieve script that contains an extreme numeric literal. This action triggers an out-of-bounds write during the compilation of the script, resulting in memory corruption. The immediate effect is a crash of the ManageSieve process, leading to a denial of service for script management. Furthermore, this flaw could potentially be exploited for remote code execution. Users are strongly advised to disable the ManageSieve service if remote Sieve script management is not required and to update to the latest patched versions to mitigate risks.

Affected Version(s)

OX Dovecot CE 2.3.0 < 2.4.5

OX Dovecot Pro 2.3.0 < 2.3.22.2

OX Dovecot Pro 3.0.0 < 3.0.7

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.