CVE-2026-40014
Deferred Deferred - Pending Action

IMAP THREAD Command CPU Exhaustion in Open-Xchange

Vulnerability report for CVE-2026-40014, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-28

Last updated on: 2026-09-03

Assigner: Open-Xchange

Description

An attacker that can send mail to a user can craft a message header that makes the IMAP THREAD command consume CPU disproportionate to the size of the message. When a mail client issues a THREAD command on the affected mailbox, this can cause degradation or denial of service for IMAP. Monitor system for abnormal CPU usage, kill the offending process and remove the offending message from the affected mailbox. Update to non-vulnerable version. No publicly available exploits are known.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-28
Last Modified
2026-09-03
Generated
2026-09-18
AI Q&A
2026-08-28
EPSS Evaluated
2026-09-15
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
open-xchange imap *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows an attacker to send a specially crafted email that triggers excessive CPU usage when an IMAP client processes the THREAD command on the affected mailbox. This can lead to system slowdowns or complete denial of service for IMAP services.

Detection Guidance

Monitor system for abnormal CPU usage during IMAP operations. Check for processes consuming excessive CPU when the THREAD command is used. Use system monitoring tools like top, htop, or ps to identify high CPU usage by IMAP-related processes.

Impact Analysis

If exploited, this vulnerability can degrade or crash your IMAP server, making email services unavailable. Users may experience slow performance or inability to access their emails. The impact is higher if the server handles many users or large mailboxes.

Compliance Impact

This vulnerability causes denial of service through CPU exhaustion, which could disrupt availability of IMAP services. For GDPR, this may impact data access rights if users cannot retrieve emails. For HIPAA, service disruption could affect timely access to protected health information.

Mitigation Strategies

Kill the offending process causing high CPU usage. Remove the malicious message from the affected mailbox. Update to a non-vulnerable version of the IMAP service.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-40014. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart