CVE-2026-33603
Attacker can use a specially crafted base64 exchange between Dovecot and Client to fake SCRAM TLS channel binding. This requires that the attacker is able to position itself between Dovecot and the client connection. If successful, the attacker can eavesdrop communications between Dovecot and client as MITM proxy. Install fixed version. No publicly available exploits are known.
- Dovecot
- < 2.4.4
- Open-xchange Dovecot
- < 3.1.5
- Fix
- Available
- CVSS 3.1
- 6.8 MEDIUM
- EPSS
- 0.2% (12th percentile)
- Weakness
- CWE-99
- NVD status
- Analyzed
- Published
- 2026-05-12
CVE-2026-33603 at NVD
No indexed exploits for CVE-2026-33603 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2026-33603 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.