PT-2026-28363 · Dovecot+2 · Dovecot+2

Hamizanazman

·

Publicado

2026-01-01

·

Atualizado

2026-04-16

·

CVE-2026-27855

CVSS v3.1

6.8

Média

VetorAV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Dovecot versions prior to 2.4.3
Description Dovecot OTP authentication is susceptible to a replay attack under certain conditions. Specifically, if the authentication cache is enabled and a username is modified within the passdb, OTP credentials can be cached, allowing the same OTP reply to be valid for subsequent login attempts. An attacker observing an OTP exchange could potentially log in as the user. The issue occurs when authentication happens over an unsecure connection.
Recommendations Update to version 2.4.3 or later. If updating is not immediately possible, switch to the SCRAM protocol. Ensure communications are secured. If possible, switch to OAUTH2 or SCRAM.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-27855
OESA-2026-1849
OPENSUSE-SU-2026:10442-1
OPENSUSE-SU-2026:20554-1
SUSE-SU-2026:21208-1
USN-8136-1

Produtos afetados

Dovecot
Linuxmint
Ubuntu