Dovecot: 17 Vulnerabilities Including Critical Flaws Disclosed Together on August 28, 2026
Open-Xchange's Dovecot mail server is affected by 17 vulnerabilities disclosed on August 28, 2026, including critical flaws in IMAP and Sieve functionalities.

Key findings
- 17 Dovecot vulnerabilities disclosed on August 28, 2026, ranging from Low to Critical severity.
- Critical flaw CVE-2026-42007 involves use-after-free in mail editing via Sieve scripts.
- Multiple IMAP-related vulnerabilities can lead to denial of service through excessive CPU or memory usage.
- Authentication bypass and memory disclosure vulnerabilities also present significant risks.
- Users are urged to update Dovecot to patched versions and apply specific mitigations where available.
On August 28, 2026, Open-Xchange's Dovecot mail server was impacted by a batch of 17 vulnerabilities disclosed on the same day. These vulnerabilities range in severity from Low to Critical, with a notable cluster of High and Critical severity issues, posing a significant risk to users if left unaddressed. The disclosures highlight several areas of concern within Dovecot's IMAP, Sieve, and authentication functionalities.
Several vulnerabilities center on the IMAP protocol. CVE-2026-73209, a Medium severity flaw, allows authenticated attackers to cause a stack exhaustion and crash by sending crafted compressed data, leading to denial of service for IMAP. Similarly, CVE-2026-40015 (Medium) permits authenticated users to exploit a weakness in the imap-hibernate service by opening numerous connections and sending invalid commands, resulting in out-of-bounds reads and process crashes, disrupting hibernated IMAP sessions. CVE-2026-40014 and CVE-2026-40017, both Medium severity, enable attackers with valid credentials or the ability to send mail to a user to craft specific message headers that cause the IMAP THREAD command to consume excessive CPU, leading to denial of service. CVE-2026-42392 (Medium) involves an invalid IMAP URLFETCH command that can disclose process memory contents, potentially including sensitive data. CVE-2026-33607 (Medium) allows authenticated users to consume excessive CPU via the IMAP LIST command, impacting IMAP availability. Finally, CVE-2026-27852 (High) involves crafting messages with a large number of email addresses or MIME parameters, leading to excessive memory usage during parsing and potential process termination when accessed via IMAP.
Authentication and authorization mechanisms were also targeted. CVE-2026-40205, a Medium severity vulnerability, allows an attacker with a partial OAuth2 token to authenticate due to an inconsistency between remote and local token validation paths. CVE-2026-42395 (Medium) enables a trusted proxy to send forwarding information with a NUL byte, crashing the login process on subsequent attempts.
Other critical areas affected include Sieve scripting and mail processing. CVE-2026-42007, a Critical severity flaw, allows authenticated users to trigger a use-after-free vulnerability in mail editing code via Sieve scripts with the editheader extension, leading to memory corruption and potential data leakage during mail delivery. CVE-2026-40018 (High) and CVE-2026-40013 (Medium) also present significant risks, with the former's details not fully elaborated in the provided information, and the latter allowing authenticated users to cause an out-of-bounds write in the ManageSieve service by submitting extreme numeric literals in Sieve scripts, leading to process crashes. CVE-2026-33606 (Medium) allows crafted mail content to be interpreted as dsync protocol commands during migration or replication, potentially modifying mailbox state. CVE-2026-33604 (Medium) enables bypassing outbound protection by using a crafted line ending in the message body, potentially allowing downstream servers to interpret SMTP commands. CVE-2026-33263 (Medium) can cause submission-login to crash due to file descriptor handling issues when a specific connection limit is reached.
The batch also includes two Low severity vulnerabilities: CVE-2026-40204 and CVE-2026-40203. The former's description is minimal, while the latter relates to IMAP compression, where reused compression states can allow an attacker to confirm whether certain mail exists by observing IMAP traffic sizes.
Open-Xchange has provided updates to address these vulnerabilities. Users are strongly advised to update to non-vulnerable versions of Dovecot. Specific mitigations are available for some issues, such as disabling IMAP URLAUTH functionality for CVE-2026-42392 and restricting trusted proxies for CVE-2026-42395. For CVE-2026-40014 and CVE-2026-40013, monitoring system for abnormal CPU usage and restarting offending processes are suggested as temporary measures.
This coordinated disclosure of 17 vulnerabilities underscores the importance of timely patching and configuration management for Dovecot deployments. The range of affected components, from core IMAP functionality to authentication and scripting, necessitates a comprehensive review of security practices and prompt application of available updates to mitigate risks of denial of service, data disclosure, and memory corruption.
CVE-2026-73209 CVE-2026-42395 CVE-2026-42392 CVE-2026-42007 CVE-2026-40205 CVE-2026-40204 CVE-2026-40203 CVE-2026-40018 CVE-2026-40017 CVE-2026-40015 CVE-2026-40014 CVE-2026-40013 CVE-2026-33607 CVE-2026-33606 CVE-2026-33604 CVE-2026-33263 CVE-2026-27852