Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-81704.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-81704
Upstream
Published
2026-03-27T09:16:19Z
Modified
2026-08-30T05:24:52Z
Summary
CVE-2026-27856 affecting package dovecot 2.3.20-1
Details

Doveadm credentials are verified using direct comparison which is susceptible to timing oracle attack. An attacker can use this to determine the configured credentials. Figuring out the credential will lead into full access to the affected component. Limit access to the doveadm http service port, install fixed version. No publicly available exploits are known.

References

Affected packages

Azure Linux:3 / dovecot

Package

Name
dovecot
Purl
pkg:rpm/azure-linux/dovecot

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
2.3.20-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-81704.json"