SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-40013

MEDIUM · CVSS 4.3 EPSS 0.46% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-28 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The vulnerability affects the ManageSieve service, allowing authenticated attackers to exploit an out-of-bounds write through a specially crafted Sieve script, leading to memory corruption and potential denial of service. This issue may also open the door for remote code execution under certain conditions. Organizations utilizing the ManageSieve service should prioritize addressing this vulnerability by disabling the service if not needed and updating to a secure version.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit remote code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-40013
Severity
MEDIUM
CVSS
4.3
EPSS
0.46%

Original NVD Description

An attacker that has valid credentials can submit a Sieve script containing an extreme numeric literal, which causes an out-of-bounds write when the ManageSieve service compiles the script. This causes memory corruption and an observed crash of the ManageSieve process, resulting in denial of service for script management. This might be able to be used for remote code execution. Disable the ManageSieve service if users do not need remote Sieve script management. Update to non-vulnerable version. No publicly available exploits are known.