IMAP Service Vulnerability in Open-Xchange Dovecot
CVE-2026-40015

4.3MEDIUM

What is CVE-2026-40015?

An attacker with valid credentials can exploit the imap-hibernate service by establishing multiple connections and sending malformed commands. This action can result in an out-of-bounds read condition which may intermittently crash the associated process, affecting IMAP sessions in hibernation. The compromised service leads to interruptions and a noticeable degradation of service quality for users. To mitigate potential risks, it is advised to disable IMAP hibernation and ensure the use of updated, secure versions of the affected product. There are currently no known public exploits for this vulnerability.

Affected Version(s)

OX Dovecot CE 2.3.0 < 2.4.5

OX Dovecot Pro 2.3.0 < 2.3.22.2

OX Dovecot Pro 3.0.0 < 3.0.7

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.