CVEFinder.io

CVE-2026-33603

đŸ”ļ medium
🔍 Scan for this CVE
Summary

Attacker can use a specially crafted base64 exchange between Dovecot and Client to fake SCRAM TLS channel binding. This requires that the attacker is able to position itself between Dovecot and the client connection. If successful, the attacker can eavesdrop communications between Dovecot and client as MITM proxy. Install fixed version. No publicly available exploits are known.

CVSS Score
6.8
Medium
EPSS Score
0.0
Exploit Probability
Published Date
2026-05-12
First Seen: 2026-05-19
📊 Relative Risk Intelligence

This CVE is Lower Risk - more severe than 48.9% of all 321,566 vulnerabilities in our database.

#164,380
Below average severity
Severity Percentile
đŸŽ¯ CISA SSVC Assessment Updated: May 12, 2026
🔍 Exploitation Status
None
No known exploits
âš™ī¸ Automatable
NO
Requires human interaction
đŸ’Ĩ Technical Impact
Total
Complete system compromise possible
SSVC data provided by CISA
Last Modified 2026-05-18
CVSS Vector 3.1 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
CWE IDs (Weakness Types)

đŸ“Ļ Affected Products 1

🔗 References 1

🔗 Related CVEs 6

CVE ID Severity CVSS EPSS Summary Published
CVE-2026-27851 âš ī¸ high 7.4 0.0 When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted... 2026-05-12
CVE-2026-40016 đŸ”ļ medium 5.3 0.0 Attacker can upload a malicious Sieve script over ManageSieve service (or locally) to bypass configured CPU time limits ... 2026-05-12
CVE-2026-40020 â„šī¸ low 3.1 0.0 Attacker can use the IMAP SETACL command to inject the anyone permission to user's dovecot-acl file even if imap_acl_all... 2026-05-12
CVE-2026-42006 đŸ”ļ medium 4.3 0.0 An attacker can cause uncontrolled memory usage with excessive bracing over IMAP. The fix in CVE-2026-27857 was incomple... 2026-05-12
CVE-2025-59028 đŸ”ļ medium 5.3 0.1 When sending invalid base64 SASL data, login process is disconnected from the auth server, causing all active authentica... 2026-03-27
CVE-2025-59032 âš ī¸ high 7.5 0.1 ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSi... 2026-03-27
These CVEs affect the same products