CVE-2026-27855

Name
CVE-2026-27855
Description
Dovecot OTP authentication is vulnerable to replay attack under specific conditions. If auth cache is enabled, and username is altered in passdb, then OTP credentials can be cached so that same OTP reply is valid. An attacker able to observe an OTP exchange is able to log in as the user. If authentication happens over unsecure connection, switch to SCRAM protocol. Alternatively ensure the communcations are secured, and if possible switch to OAUTH2 or SCRAM. No publicly available exploits are known.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
security@open-xchange.com https://documentation.open-xchange.com/dovecot/security/advisories/csaf/2026/oxdc-adv-2026-0001.json

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:dovecot:dovecot:*:*:*:*:*:*:*:* dovecot >= None < 2.4.3
cpe:2.3:a:open-xchange:dovecot:*:*:*:*:pro:*:*:* dovecot >= None <= 2.3.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
dovecot edge-main 2.4.3-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
dovecot edge-main 2.4.2-r2 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
dovecot edge-main 2.4.2-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
dovecot edge-main 2.4.2-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
dovecot edge-main 2.4.1-r3 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
dovecot edge-main 2.4.1-r2 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
dovecot edge-main 2.4.1-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
dovecot edge-main 2.4.1-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
dovecot edge-main 2.4.0-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
dovecot edge-main 2.4.0-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
dovecot edge-main 2.3.21.1-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
dovecot edge-main 2.3.19.1-r6 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
dovecot edge-main 2.3.19.1-r5 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
dovecot edge-main 2.3.15-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
dovecot edge-main 2.3.13-r0 None possibly vulnerable
dovecot edge-main 2.3.11.3-r0 None possibly vulnerable
dovecot edge-main 2.3.10.1-r0 None possibly vulnerable
dovecot edge-main 2.3.9.3-r0 None possibly vulnerable
dovecot edge-main 2.3.9.2-r0 None possibly vulnerable
dovecot edge-main 2.3.7.2-r0 None possibly vulnerable
dovecot edge-main 2.3.6-r0 None possibly vulnerable
dovecot edge-main 2.3.5.1-r0 None possibly vulnerable
dovecot edge-main 2.3.4.1-r0 None possibly vulnerable
dovecot edge-main 2.3.1-r0 None possibly vulnerable
dovecot 3.23-main 2.4.3-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
dovecot 3.23-main 2.4.2-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
dovecot 3.22-main 2.4.1-r2 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
dovecot 3.22-main 2.3.21.1-r0 None possibly vulnerable
dovecot 3.22-main 2.3.19.1-r5 None possibly vulnerable
dovecot 3.22-main 2.3.15-r0 None possibly vulnerable
dovecot 3.22-main 2.3.13-r0 None possibly vulnerable
dovecot 3.22-main 2.3.11.3-r0 None possibly vulnerable
dovecot 3.22-main 2.3.10.1-r0 None possibly vulnerable
dovecot 3.22-main 2.3.9.3-r0 None possibly vulnerable
dovecot 3.22-main 2.3.9.2-r0 None possibly vulnerable
dovecot 3.22-main 2.3.7.2-r0 None possibly vulnerable
dovecot 3.22-main 2.3.6-r0 None possibly vulnerable
dovecot 3.22-main 2.3.5.1-r0 None possibly vulnerable
dovecot 3.22-main 2.3.4.1-r0 None possibly vulnerable
dovecot 3.22-main 2.3.1-r0 None possibly vulnerable
dovecot 3.21-main 2.3.21.1-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
dovecot 3.21-main 2.3.19.1-r5 None possibly vulnerable
dovecot 3.21-main 2.3.15-r0 None possibly vulnerable
dovecot 3.21-main 2.3.13-r0 None possibly vulnerable
dovecot 3.21-main 2.3.11.3-r0 None possibly vulnerable
dovecot 3.21-main 2.3.10.1-r0 None possibly vulnerable
dovecot 3.21-main 2.3.9.3-r0 None possibly vulnerable
dovecot 3.21-main 2.3.9.2-r0 None possibly vulnerable
dovecot 3.21-main 2.3.7.2-r0 None possibly vulnerable
dovecot 3.21-main 2.3.6-r0 None possibly vulnerable
dovecot 3.21-main 2.3.5.1-r0 None possibly vulnerable
dovecot 3.21-main 2.3.4.1-r0 None possibly vulnerable
dovecot 3.21-main 2.3.1-r0 None possibly vulnerable
dovecot 3.20-main 2.3.21.1-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
dovecot 3.20-main 2.3.19.1-r5 None possibly vulnerable
dovecot 3.20-main 2.3.15-r0 None possibly vulnerable
dovecot 3.20-main 2.3.13-r0 None possibly vulnerable
dovecot 3.20-main 2.3.11.3-r0 None possibly vulnerable
dovecot 3.20-main 2.3.10.1-r0 None possibly vulnerable
dovecot 3.20-main 2.3.9.3-r0 None possibly vulnerable
dovecot 3.20-main 2.3.9.2-r0 None possibly vulnerable
dovecot 3.20-main 2.3.7.2-r0 None possibly vulnerable
dovecot 3.20-main 2.3.6-r0 None possibly vulnerable
dovecot 3.20-main 2.3.5.1-r0 None possibly vulnerable
dovecot 3.20-main 2.3.4.1-r0 None possibly vulnerable
dovecot 3.20-main 2.3.1-r0 None possibly vulnerable
dovecot 3.19-main 2.3.21-r17 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
dovecot 3.19-main 2.3.19.1-r5 None possibly vulnerable
dovecot 3.19-main 2.3.15-r0 None possibly vulnerable
dovecot 3.19-main 2.3.13-r0 None possibly vulnerable
dovecot 3.19-main 2.3.11.3-r0 None possibly vulnerable
dovecot 3.19-main 2.3.10.1-r0 None possibly vulnerable
dovecot 3.19-main 2.3.9.3-r0 None possibly vulnerable
dovecot 3.19-main 2.3.9.2-r0 None possibly vulnerable
dovecot 3.19-main 2.3.7.2-r0 None possibly vulnerable
dovecot 3.19-main 2.3.6-r0 None possibly vulnerable
dovecot 3.19-main 2.3.5.1-r0 None possibly vulnerable
dovecot 3.19-main 2.3.4.1-r0 None possibly vulnerable
dovecot 3.19-main 2.3.1-r0 None possibly vulnerable