CVE-2026-27855: Medium severity Dovecot dovecot vulnerability

Published Mar 27, 2026
·
Updated

Dovecot OTP authentication is vulnerable to replay attack under specific conditions. If auth cache is enabled, and username is altered in passdb, then OTP credentials can be cached so that same OTP reply is valid. An attacker able to observe an OTP exchange is able to log in as the user. If authentication happens over unsecure connection, switch to SCRAM protocol. Alternatively ensure the communcations are secured, and if possible switch to OAUTH2 or SCRAM. No publicly available exploits are known.

Affected Software

3 affected components
Dovecot dovecot
Dovecot dovecot<2.4.3
Open-Xchange Dovecot<=2.3.0

Event History

Mar 27, 2026
CVE Published
via MITRE·08:10 AM
Data Sourced
via MITRE·08:10 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-27855?

CVE-2026-27855 is considered a medium severity vulnerability due to the risk of replay attacks.

2

How do I fix CVE-2026-27855?

To fix CVE-2026-27855, ensure that the auth cache is disabled or properly configured to mitigate the replay attack risk.

3

What systems are affected by CVE-2026-27855?

CVE-2026-27855 affects Dovecot installations that have OTP authentication with auth cache enabled.

4

What is a replay attack in the context of CVE-2026-27855?

A replay attack in CVE-2026-27855 occurs when an attacker reuses a valid OTP to gain unauthorized access if the OTP is cached.

5

How can an attacker exploit CVE-2026-27855?

An attacker can exploit CVE-2026-27855 by observing an OTP exchange and later using the cached OTP for authentication.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203