Логотип exploitDog
bind:CVE-2026-27856
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2026-27856

Количество 4

Количество 4

redhat логотип

CVE-2026-27856

5 дней назад

A flaw was found in Doveadm, a component of Dovecot. An attacker can exploit a timing oracle vulnerability during the direct comparison of credentials. This allows the attacker to determine the configured credentials, potentially leading to full unauthorized access to the affected component.

CVSS3: 7.4
EPSS: Низкий
nvd логотип

CVE-2026-27856

5 дней назад

Doveadm credentials are verified using direct comparison which is susceptible to timing oracle attack. An attacker can use this to determine the configured credentials. Figuring out the credential will lead into full access to the affected component. Limit access to the doveadm http service port, install fixed version. No publicly available exploits are known.

CVSS3: 7.4
EPSS: Низкий
debian логотип

CVE-2026-27856

5 дней назад

Doveadm credentials are verified using direct comparison which is susc ...

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-mv3x-9fw3-qf38

5 дней назад

Doveadm credentials are verified using direct comparison which is susceptible to timing oracle attack. An attacker can use this to determine the configured credentials. Figuring out the credential will lead into full access to the affected component. Limit access to the doveadm http service port, install fixed version. No publicly available exploits are known.

CVSS3: 7.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2026-27856

A flaw was found in Doveadm, a component of Dovecot. An attacker can exploit a timing oracle vulnerability during the direct comparison of credentials. This allows the attacker to determine the configured credentials, potentially leading to full unauthorized access to the affected component.

CVSS3: 7.4
0%
Низкий
5 дней назад
nvd логотип
CVE-2026-27856

Doveadm credentials are verified using direct comparison which is susceptible to timing oracle attack. An attacker can use this to determine the configured credentials. Figuring out the credential will lead into full access to the affected component. Limit access to the doveadm http service port, install fixed version. No publicly available exploits are known.

CVSS3: 7.4
0%
Низкий
5 дней назад
debian логотип
CVE-2026-27856

Doveadm credentials are verified using direct comparison which is susc ...

CVSS3: 7.4
0%
Низкий
5 дней назад
github логотип
GHSA-mv3x-9fw3-qf38

Doveadm credentials are verified using direct comparison which is susceptible to timing oracle attack. An attacker can use this to determine the configured credentials. Figuring out the credential will lead into full access to the affected component. Limit access to the doveadm http service port, install fixed version. No publicly available exploits are known.

CVSS3: 7.4
0%
Низкий
5 дней назад

Уязвимостей на страницу