Description
Sieve CPU resource usage is tracked in the compiled script, so an attacker that has valid credentials can reset the accounting by repeatedly changing the active script. Compiled script files are also not removed when a script is deleted or renamed. The configured Sieve CPU limit can be bypassed, allowing sustained CPU consumption, and the leftover files increase disk consumption. Both can cause degradation of service for mail delivery. Monitor system for abnormal CPU usage and disk consumption. Update to non-vulnerable version. No publicly available exploits are known.
Published: 2026-08-28
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: Resource Exhaustion
Action: Patch
AI Analysis

Impact

Compiled Sieve scripts in OX Dovecot track CPU consumption, but an attacker with valid credentials can reset this accounting by repeatedly activating different scripts. This loophole also leaves behind compiled script files when a script is deleted or renamed, allowing the configured CPU limit to be bypassed and enabling continuous high CPU use. The orphaned files grow disk space, both leading to service degradation for mail delivery.

Affected Systems

Vulnerable versions are found in Open‑Xchange GmbH's OX Dovecot Community Edition and Pro Edition. Specific version numbers are not publicly documented, so any installation of these products should be evaluated.

Risk and Exploitability

With a CVSS score of 3.1, the vulnerability is modestly serious, yet still presents a tangible risk of service disruption. Exploitation requires legitimate account credentials, limiting the threat to insiders or compromised accounts. No public exploits are known, and the EPSS score is <1%, indicating a very low exploitation probability. Because the issue can degrade mail delivery, administrators should consider the vulnerability a low‑to‑moderate risk depending on the criticality of the mail service.

Generated by OpenCVE AI on September 1, 2026 at 14:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑provided update to the latest version of OX Dovecot CE or Pro that fixes the accounting reset and file cleanup issue.
  • Re‑apply the Sieve CPU quota after updating, ensuring the limit is enforced.
  • Remove any residual compiled script files that may have accumulated on the system.
  • Continuously monitor CPU utilisation and disk usage for abnormal levels that could indicate misuse or leftover files.

Generated by OpenCVE AI on September 1, 2026 at 14:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Open-xchange
Open-xchange ox Dovecot Ce
Open-xchange ox Dovecot Pro
Vendors & Products Open-xchange
Open-xchange ox Dovecot Ce
Open-xchange ox Dovecot Pro

Tue, 01 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Title Sieve CPU Bypass and Residual File Drain in Open‑Xchange Dovecot dovecot: Dovecot: Denial of Service via Sieve script manipulation
Weaknesses CWE-770
References
Metrics threat_severity

None

threat_severity

Low


Fri, 28 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 28 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Title Sieve CPU Bypass and Residual File Drain in Open‑Xchange Dovecot

Fri, 28 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
Description Sieve CPU resource usage is tracked in the compiled script, so an attacker that has valid credentials can reset the accounting by repeatedly changing the active script. Compiled script files are also not removed when a script is deleted or renamed. The configured Sieve CPU limit can be bypassed, allowing sustained CPU consumption, and the leftover files increase disk consumption. Both can cause degradation of service for mail delivery. Monitor system for abnormal CPU usage and disk consumption. Update to non-vulnerable version. No publicly available exploits are known.
Weaknesses CWE-1050
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Open-xchange Ox Dovecot Ce Ox Dovecot Pro
cve-icon MITRE

Status: PUBLISHED

Assigner: OX

Published:

Updated: 2026-08-28T15:53:36.937Z

Reserved: 2026-06-08T08:05:31.707Z

Link: CVE-2026-52681

cve-icon Vulnrichment

Updated: 2026-08-28T14:32:27.005Z

cve-icon NVD

Status : Deferred

Published: 2026-08-28T12:16:30.010

Modified: 2026-09-03T18:13:44.643

Link: CVE-2026-52681

cve-icon Redhat

Severity : Low

Publid Date: 2026-08-28T10:12:30Z

Links: CVE-2026-52681 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T15:00:11Z

Weaknesses
  • CWE-1050

    Excessive Platform Resource Consumption within a Loop

  • CWE-770

    Allocation of Resources Without Limits or Throttling