PT-2026-83056 · Unknown · Managesieve

·

CVE-2026-40013

·

Published

2026-08-28

·

Updated

2026-09-01

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions ManageSieve (affected versions not specified)
Description An attacker with valid credentials can submit a Sieve script containing an extreme numeric literal. This triggers an out-of-bounds write during script compilation by the ManageSieve service, leading to memory corruption and a process crash. This results in a denial of service for script management and could potentially allow remote code execution.
Recommendations Update to a non-vulnerable version. Disable the ManageSieve service if remote Sieve script management is not required.

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-98268
CVE-2026-40013
OPENSUSE-SU-2026:21720-1

Affected Products

Managesieve