Denial of Service Vulnerability in ManageSieve by Open-Xchange
CVE-2026-40019

5.9MEDIUM

Key Information:

Vendor
CVE Published:
28 August 2026

What is CVE-2026-40019?

A vulnerability exists in Open-Xchange's ManageSieve service allowing an unauthenticated attacker to exploit a truncated quoted argument during the login process. This exploitation can lead the service into an infinite loop, excessively consuming CPU resources. As a result, it may degrade service functionality or lead to a complete denial of service for Sieve script management. It is crucial for users to monitor system performance for abnormal CPU usage and restrict network access to the ManageSieve service to trusted clients. Users should also ensure that they update to the latest non-vulnerable version to mitigate any risks associated with this issue.

Affected Version(s)

OX Dovecot CE 2.4.3 < 2.4.5

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.