CVE-2026-40016
Last modified
CVE-2026-40016 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Attacker can upload a malicious Sieve script over ManageSieve service (or locally) to bypass configured CPU time limits for Sieve up to 130 times of the configured limit. Attacker can use this to degrade server performance and bypass configured CPU time limits for Sieve scripts. EPSS estimates a 0.34% chance of exploitation in the next 30 days.
Description
Attacker can upload a malicious Sieve script over ManageSieve service (or locally) to bypass configured CPU time limits for Sieve up to 130 times of the configured limit. Attacker can use this to degrade server performance and bypass configured CPU time limits for Sieve scripts. Install fixed version, or alternatively prevent direct access to Sieve scripts via ManageSieve or local access. No publicly available exploits are known.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Dovecot | Dovecot | < 2.4.4 |
| Open-Xchange | Dovecot | < 3.1.5 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-40016?
How severe is CVE-2026-40016?
How do I fix CVE-2026-40016?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-40010Missing invocation of Servlet http web request method change…9.1
- CVE-2026-40011An attacker sending a large number of crafted DNS queries mi…3.7
- CVE-2026-40012ECS zero scoped answers are stored in the packet cache while…5.3
- CVE-2026-40013An attacker that has valid credentials can submit a Sieve sc…4.3
- CVE-2026-40014An attacker that can send mail to a user can craft a message…6.5
- CVE-2026-40015An attacker that has valid credentials can open many connect…4.3
- CVE-2026-40017An attacker that can send mail to a user can craft a message…6.5
- CVE-2026-40018None None None No publicly available exploits are known.7.4
- CVE-2026-40019An unauthenticated attacker can send a truncated quoted argu…5.9
- CVE-2026-4002The Petje.af plugin for WordPress is vulnerable to Cross-Sit…4.3
- CVE-2026-40020Attacker can use the IMAP SETACL command to inject the anyon…4.3
- CVE-2026-40021Apache Log4net's XmlLayout https://logging.apache.org/log4n…5.3
Are you affected by CVE-2026-40016?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
