PT-2026-83065 · Open Xchange Gmbh+6 · Ox Dovecot Ce+4

·

CVE-2026-42007

·

Published

2026-08-28

·

Updated

2026-09-08

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions Email servers allowing Sieve scripts (affected versions not specified)
Description An attacker with valid credentials can use a Sieve script with the editheader extension to trigger a use-after-free condition in the mail editing code. This allows writing memory contents beyond the intended buffer into the delivered mail, resulting in a memory leak and potential memory corruption during mail delivery. Such an issue can crash the delivery process and may lead to arbitrary code execution within the context of that process.
Recommendations Disable the Sieve editheader extension. Update to a non-vulnerable version.

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-98298
CVE-2026-42007
OPENSUSE-SU-2026:11629-1
OPENSUSE-SU-2026:21720-1
SUSE-SU-2026:3919-1

Affected Products

Ox Dovecot Ce
Ox Dovecot Pro
Dovecot
Dovecot22
Dovecot24