IMAP Service Vulnerability in Open-Xchange Dovecot
CVE-2026-40015
4.3MEDIUM
Key Information:
- Vendor
Open-xchange Gmbh
- Vendor
- CVE Published:
- 28 August 2026
What is CVE-2026-40015?
An attacker with valid credentials can exploit the imap-hibernate service by establishing multiple connections and sending malformed commands. This action can result in an out-of-bounds read condition which may intermittently crash the associated process, affecting IMAP sessions in hibernation. The compromised service leads to interruptions and a noticeable degradation of service quality for users. To mitigate potential risks, it is advised to disable IMAP hibernation and ensure the use of updated, secure versions of the affected product. There are currently no known public exploits for this vulnerability.
Affected Version(s)
OX Dovecot CE 2.3.0 < 2.4.5
OX Dovecot Pro 2.3.0 < 2.3.22.2
OX Dovecot Pro 3.0.0 < 3.0.7
