CVE Feed

    Dashboard / CVE / CVE-2026-33605

    CVE-2026-33605

    An unauthenticated attacker can crash the ManageSieve login process by sending a small malformed command before authenticating. If running in high-security mode (default for community releases), only the attacker's own connection is terminated. If running in high-performance mode (default for Pro releases), all connections handled by the same managesieve-login process are terminated. Repeating the attack can cause denial of service for Sieve script management. Restrict network access to the ManageSieve service to trusted clients. Update to non-vulnerable version. No publicly available exploits are known.

    Published:Aug 28, 2026
    Last Modified:Sep 1, 2026
    EPS:Aug 28, 2026
    EPSS Score:0.00375
    CVSS Score:7.5

    Affected Products

    Vendor
    Open-xchange
    Product
    Ox Dovecot Ce
    Vendor
    Open-xchange
    Product
    Ox Dovecot Pro

    Exploits

    No exploit reference

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High