Description
An attacker that has valid credentials can use a Sieve script with the editheader extension to trigger a use-after-free in the mail editing code, and to write memory contents beyond the intended buffer into the delivered mail. This causes memory leak and opportunity to do memory corruption during mail delivery, which can crash the delivery process and may allow execution of arbitrary code in the context of that process. Disable the Sieve editheader extension. Update to non-vulnerable version. No publicly available exploits are known.
Published: 2026-08-28
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch Immediately
AI Analysis

Impact

An attacker with valid credentials can submit a Sieve script that uses the editheader extension, triggering a use‑after‑free in the mail editing code. This misuse allows memory contents to be written beyond the intended buffer, leaking information and creating an opportunity for memory corruption during delivery, which can crash the process or lead to execution of arbitrary code in the mail delivery context. The flaw is based on improper memory management.

Affected Systems

The vulnerability affects Open‑Xchange GmbH's OX Dovecot CE and OX Dovecot Pro products. No specific version numbers are listed in the advisory, so all currently deployed instances should be treated as potentially impacted until an update is applied.

Risk and Exploitability

The CVSS score of 9.1 indicates critical severity, and the EPSS score is 0.00288 (0.288%). The vulnerability is not listed in the CISA KEV catalog and no public exploits have been reported. However, the weakness requires legitimate user credentials, implying that an authenticated user could craft the malicious Sieve script. Once executed, the application could crash or be hijacked for arbitrary code. The high CVSS weight combined with the low levels of exploitation probability and lack of mitigation unless patched elevates the risk significantly.

Generated by OpenCVE AI on September 1, 2026 at 14:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to a non‑vulnerable version of OX Dovecot to fix the use‑after‑free bug.
  • Disable the Sieve editheader extension in the Sieve configuration for all users to block the vulnerable functionality.
  • Remove or rename any existing Sieve scripts that use the editheader extension so they cannot be executed.

Generated by OpenCVE AI on September 1, 2026 at 14:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Open-xchange
Open-xchange ox Dovecot Ce
Open-xchange ox Dovecot Pro
Vendors & Products Open-xchange
Open-xchange ox Dovecot Ce
Open-xchange ox Dovecot Pro

Tue, 01 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Title Use-After-Free in OX Dovecot Sieve Editheader Extension Allows Potential Code Execution dovecot: Dovecot: Arbitrary Code Execution via Sieve editheader use-after-free
Weaknesses CWE-825
References
Metrics threat_severity

None

threat_severity

Important


Fri, 28 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 28 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Title Use-After-Free in OX Dovecot Sieve Editheader Extension Allows Potential Code Execution

Fri, 28 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
Description An attacker that has valid credentials can use a Sieve script with the editheader extension to trigger a use-after-free in the mail editing code, and to write memory contents beyond the intended buffer into the delivered mail. This causes memory leak and opportunity to do memory corruption during mail delivery, which can crash the delivery process and may allow execution of arbitrary code in the context of that process. Disable the Sieve editheader extension. Update to non-vulnerable version. No publicly available exploits are known.
Weaknesses CWE-416
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H'}


Subscriptions

Open-xchange Ox Dovecot Ce Ox Dovecot Pro
cve-icon MITRE

Status: PUBLISHED

Assigner: OX

Published:

Updated: 2026-08-28T15:54:24.354Z

Reserved: 2026-04-23T11:15:21.199Z

Link: CVE-2026-42007

cve-icon Vulnrichment

Updated: 2026-08-28T14:32:38.212Z

cve-icon NVD

Status : Deferred

Published: 2026-08-28T12:16:29.260

Modified: 2026-09-03T18:13:44.643

Link: CVE-2026-42007

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-28T10:12:25Z

Links: CVE-2026-42007 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T14:45:04Z

Weaknesses