CVE-2026-33605

7.5

Open-Xchange · OX Dovecot Pro

An unauthenticated attacker can trigger a denial of service in the ManageSieve login process by sending a malformed command, potentially disrupting Sieve script management.

Executive summary

A critical denial of service vulnerability in Open-Xchange OX Dovecot allows unauthenticated remote attackers to crash the ManageSieve login process.

Vulnerability

This is an uncontrolled resource consumption flaw (CWE-400) where an unauthenticated attacker can send a malformed command to the ManageSieve service, causing the process to crash. The severity of the impact depends on the configuration, with high-performance mode being particularly susceptible to widespread service termination for multiple users.

Business impact

The vulnerability carries a CVSS score of 7.5, indicating a high severity risk due to the potential for service disruption. Successful exploitation results in a denial of service for Sieve script management, which can impede email filtering and organizational mail flow configurations. While the impact is limited to availability, the ease of execution by unauthenticated actors makes this a significant operational risk for organizations relying on Dovecot for mail infrastructure.

Remediation

Immediate Action: Update OX Dovecot Pro and CE installations to the non-vulnerable versions specified in the vendor security advisory.

Proactive Monitoring: Review system and application logs for repeated, anomalous connection attempts or frequent crashes of the managesieve-login process.

Compensating Controls: Restrict network access to the ManageSieve service to only known, trusted IP addresses or internal subnets to prevent unauthorized remote interaction.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Organizations utilizing affected versions of Open-Xchange OX Dovecot should prioritize patching to the latest secure versions as soon as possible. Given that the service is often exposed to facilitate mail management, failure to patch or restrict network access leaves the infrastructure vulnerable to trivial service disruption. Apply the vendor updates immediately to eliminate this attack vector.

More Open-Xchange CVEs

Sources