CVE-2026-40015
Last modified
CVE-2026-40015 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. An attacker that has valid credentials can open many connections to the imap-hibernate service and send invalid commands, which can intermittently cause an out-of-bounds read and crash the process. The crash interrupts hibernated IMAP sessions handled by the affected process, which can cause degradation of service for IMAP. EPSS estimates a 0.29% chance of exploitation in the next 30 days.
Description
An attacker that has valid credentials can open many connections to the imap-hibernate service and send invalid commands, which can intermittently cause an out-of-bounds read and crash the process. The crash interrupts hibernated IMAP sessions handled by the affected process, which can cause degradation of service for IMAP. Disable IMAP hibernation. Update to non-vulnerable version. No publicly available exploits are known.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Open-Xchange GmbH | OX Dovecot Pro | >= 2.3.0, < 2.3.22.2; >= 3.0.0, < 3.0.7; >= 3.1.0, < 3.1.6 |
| Open-Xchange GmbH | OX Dovecot CE | >= 2.3.0, < 2.4.5 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-40015?
How severe is CVE-2026-40015?
How do I fix CVE-2026-40015?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-4001The Woocommerce Custom Product Addons Pro plugin for WordPre…9.8
- CVE-2026-40010Missing invocation of Servlet http web request method change…9.1
- CVE-2026-40011An attacker sending a large number of crafted DNS queries mi…3.7
- CVE-2026-40012ECS zero scoped answers are stored in the packet cache while…5.3
- CVE-2026-40013An attacker that has valid credentials can submit a Sieve sc…4.3
- CVE-2026-40014An attacker that can send mail to a user can craft a message…6.5
- CVE-2026-40016Attacker can upload a malicious Sieve script over ManageSiev…6.5
- CVE-2026-40017An attacker that can send mail to a user can craft a message…6.5
- CVE-2026-40018None None None No publicly available exploits are known.7.4
- CVE-2026-40019An unauthenticated attacker can send a truncated quoted argu…5.9
- CVE-2026-4002The Petje.af plugin for WordPress is vulnerable to Cross-Sit…4.3
- CVE-2026-40020Attacker can use the IMAP SETACL command to inject the anyon…4.3
Are you affected by CVE-2026-40015?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
