Executive brief
Dovecot, a widely used email server, contains a security flaw in its administrative tool (doveadm). An attacker can exploit a timing discrepancy during password verification to guess administrative credentials. If successful, the attacker could gain full administrative access to the email service, potentially allowing them to access or modify user data and system configurations.
Technical details
A timing oracle vulnerability exists in the doveadm component of Dovecot due to the use of direct string comparison for credential verification. Because standard string comparison functions often return early upon finding a mismatch, an attacker can measure the time taken for the server to respond to various authentication attempts to determine the correct characters of a password. This attack is typically performed over the network against the doveadm HTTP service port. Successful exploitation allows an attacker to recover administrative credentials, leading to unauthorized access and full control over the Dovecot instance. Users are advised to restrict access to the doveadm HTTP port and upgrade to fixed versions (e.g., Dovecot 2.4.3 or OX Dovecot Pro 3.1.4).
Affected products
- Dovecot Dovecot up to (excluding) 2.4.3
- Open-Xchange OX Dovecot Pro up to (excluding) 2.3.22.1, 3.0.0 to 3.0.5, 3.1.0 to 3.1.4
- Red Hat Red Hat Enterprise Linux Server (v. 7 ELS) 7
Timeline
- 2026-03-27: advisory: Initial public release of the advisory
- 2026-06-17: patched: Red Hat released security updates for RHEL 7 ELS
References
- https://documentation.open-xchange.com/dovecot/security/advisories/csaf/2026/oxdc-adv-2026-0001.json
- https://access.redhat.com/errata/RHSA-2026:26564
- https://access.redhat.com/security/cve/CVE-2026-27856
- https://bugzilla.redhat.com/show_bug.cgi?id=2452171
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27856.json