Authentication Bypass by Capture-replay in Dovecot - CVE-2026-27855

 

Authentication Bypass by Capture-replay in Dovecot - CVE-2026-27855

Published: April 1, 2026 / Updated: April 1, 2026


Vulnerability identifier: #VU124731
CSH Severity: Medium
CVSS v4: 7.4 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-27855
CWE-ID: CWE-294
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication.

The vulnerability exists due to authentication bypass by capture-replay in OTP authentication driver when caching credentials. A remote attacker can capture and replay OTP credentials to bypass authentication.

User interaction is required to trigger the initial authentication, and auth cache must be enabled with username alteration in passdb.


Affected software

Dovecot
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
openEuler
Ubuntu
dovecot22-backend-pgsql-debuginfo
dovecot22-backend-sqlite
dovecot22-devel
dovecot22
dovecot22-debuginfo
dovecot22-backend-pgsql
dovecot22-backend-mysql-debuginfo
dovecot22-backend-sqlite-debuginfo
dovecot22-debugsource
dovecot22-backend-mysql
dovecot-help
dovecot-devel
dovecot-debugsource
dovecot-debuginfo
dovecot
dovecot (Ubuntu package)

How to mitigate CVE-2026-27855

Install security update from vendor's website.

Dovecot - update to 2.4.3
dovecot22-backend-pgsql-debuginfo - update to 2.2.31-19.32.1
dovecot22-backend-sqlite - update to 2.2.31-19.32.1
dovecot22-devel - update to 2.2.31-19.32.1
dovecot22 - update to 2.2.31-19.32.1
dovecot22-debuginfo - update to 2.2.31-19.32.1
dovecot22-backend-pgsql - update to 2.2.31-19.32.1
dovecot22-backend-mysql-debuginfo - update to 2.2.31-19.32.1
dovecot22-backend-sqlite-debuginfo - update to 2.2.31-19.32.1
dovecot22-debugsource - update to 2.2.31-19.32.1
dovecot22-backend-mysql - update to 2.2.31-19.32.1
dovecot-help - update to 2.3.15-7
dovecot-devel - update to 2.3.15-7
dovecot-debugsource - update to 2.3.15-7
dovecot-debuginfo - update to 2.3.15-7
dovecot - update to 2.3.15-7
dovecot (Ubuntu package) - addressed in versions 1:2.3.16+dfsg1-3ubuntu2.7, 1:2.3.16+dfsg1-3ubuntu2.8, 1:2.3.21+dfsg1-2ubuntu6.3, 1:2.3.21+dfsg1-2ubuntu6.4, 1:2.4.1+dfsg1-5ubuntu4.1

External References

Related Security Bulletins