Vulnerability Description
Attacker can use a specially crafted base64 exchange between Dovecot and Client to fake SCRAM TLS channel binding. This requires that the attacker is able to position itself between Dovecot and the client connection. If successful, the attacker can eavesdrop communications between Dovecot and client as MITM proxy. Install fixed version. No publicly available exploits are known.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dovecot | Dovecot | < 2.4.4 |
| Open-Xchange | Dovecot | < 3.1.5 |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-33603?
CVE-2026-33603 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Attacker can use a specially crafted base64 exchange between Dovecot and Client to fake SCRAM TLS channel binding. This requires that the attacker is able to position itself between Dovecot and the cl...
How severe is CVE-2026-33603?
CVE-2026-33603 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-33603?
Check the references section above for vendor advisories and patch information. Affected products include: Dovecot Dovecot, Open-Xchange Dovecot.