CVE-2026-40019
Deferred Deferred - Pending Action

Denial of Service in Cyrus IMAP ManageSieve

Vulnerability report for CVE-2026-40019, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-28

Last updated on: 2026-09-03

Assigner: Open-Xchange

Description

An unauthenticated attacker can send a truncated quoted argument to the ManageSieve login process, which makes it spin in an infinite loop consuming CPU. This can cause degradation or denial of service for Sieve script management, and repeated connections can consume all available CPU on the server. Monitor system for abnormal CPU usage and kill the offending process. Restrict network access to the ManageSieve service to trusted clients. Update to non-vulnerable version. No publicly available exploits are known.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-28
Last Modified
2026-09-03
Generated
2026-09-17
AI Q&A
2026-08-28
EPSS Evaluated
2026-09-15
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
open-xchange managesieve *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows an unauthenticated attacker to send a specially crafted truncated quoted argument to the ManageSieve login process. This causes the process to enter an infinite loop, consuming excessive CPU resources. The issue leads to degraded performance or complete denial of service for Sieve script management functions.

Detection Guidance

Monitor system CPU usage for abnormal spikes. Use commands like 'top', 'htop', or 'ps aux' to identify processes consuming excessive CPU. Check ManageSieve service logs for repeated login attempts or errors.

Impact Analysis

The vulnerability can cause high CPU usage on the server, leading to slow performance or crashes. Repeated exploitation may consume all available CPU resources, making the system unresponsive. This affects the ManageSieve service specifically, disrupting email filtering and script management tasks.

Compliance Impact

This vulnerability causes denial of service by consuming all CPU resources, which could disrupt services handling sensitive data. For GDPR, this may impact availability of personal data processing systems. For HIPAA, service disruption could affect systems managing protected health information. Organizations must ensure mitigation measures like restricting access and monitoring CPU usage to maintain compliance.

Mitigation Strategies

Restrict network access to the ManageSieve service to trusted clients only. Update to a non-vulnerable version of the software. Kill any offending processes consuming high CPU.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-40019. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart