Junglewise Threat Intelligence

CVE-2026-33603: Open-Xchange Dovecot SCRAM TLS channel binding spoofing

CVE-2026-33603 · Severity: medium · CVSS 6.8 · Published 2026-05-12

Technologies: Open-Xchange Dovecot CE, Dovecot, Open-Xchange Dovecot Pro. Vendors: Open-Xchange, Dovecot.

Executive brief

A vulnerability in the Dovecot email server allows an attacker positioned on the same local network to intercept and eavesdrop on encrypted communications. By manipulating the authentication process, the attacker can bypass security checks that verify the identity of the server. This could lead to the exposure of sensitive user data and login credentials.

Technical details

A vulnerability exists in Dovecot's implementation of SCRAM authentication where an attacker can craft a malicious base64 exchange to spoof TLS channel binding. The flaw is categorized as improper control of resource identifiers (CWE-99). To exploit this, an attacker must be able to position themselves between the Dovecot server and the client (Man-in-the-Middle). If successful, the attacker can bypass the integrity protection provided by channel binding, allowing them to decrypt and eavesdrop on the communication session. The vulnerability is addressed in Dovecot Pro 3.1.5 and Dovecot CE 2.4.4.

Affected products

  • Open-Xchange Dovecot Pro 2.3.0, 3.0.5, 3.1.0, 3.1.4
  • Open-Xchange Dovecot CE 2.4.0, 2.4.3

Timeline

  • 2026-05-05: patched: Initial internal release of fix
  • 2026-05-12: disclosed: Public advisory published

References

Related threats