Out-of-Bounds Write Vulnerability in Dovecot ManageSieve Service
CVE-2026-40013
Key Information:
- Vendor
Open-xchange Gmbh
- Vendor
- CVE Published:
- 28 August 2026
What is CVE-2026-40013?
An authenticated attacker can exploit a vulnerability in the Dovecot ManageSieve service by submitting a specially crafted Sieve script that contains an extreme numeric literal. This action triggers an out-of-bounds write during the compilation of the script, resulting in memory corruption. The immediate effect is a crash of the ManageSieve process, leading to a denial of service for script management. Furthermore, this flaw could potentially be exploited for remote code execution. Users are strongly advised to disable the ManageSieve service if remote Sieve script management is not required and to update to the latest patched versions to mitigate risks.
Affected Version(s)
OX Dovecot CE 2.3.0 < 2.4.5
OX Dovecot Pro 2.3.0 < 2.3.22.2
OX Dovecot Pro 3.0.0 < 3.0.7
