CVE-2026-33603: Medium severity Dovecot dovecot vulnerability
Attacker can use a specially crafted base64 exchange between Dovecot and Client to fake SCRAM TLS channel binding. This requires that the attacker is able to position itself between Dovecot and the client connection. If successful, the attacker can eavesdrop communications between Dovecot and client as MITM proxy. Install fixed version. No publicly available exploits are known.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33603?
CVE-2026-33603 is classified as a high severity vulnerability due to the potential for an attacker to eavesdrop on communications.
How do I fix CVE-2026-33603?
To fix CVE-2026-33603, it is recommended to update Dovecot to the latest version that patches this vulnerability.
What types of attacks are possible with CVE-2026-33603?
CVE-2026-33603 allows an attacker to spoof SCRAM TLS channel binding and intercept communications between Dovecot and the client.
Who is affected by CVE-2026-33603?
CVE-2026-33603 affects all versions of Dovecot vulnerable to the specially crafted base64 attack vector.
Can CVE-2026-33603 be exploited remotely?
Yes, CVE-2026-33603 can be exploited remotely if an attacker is able to position themselves between the Dovecot server and the client.