SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-40019

MEDIUM · CVSS 5.9 EPSS 0.32% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-28 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The ManageSieve login process is vulnerable to a denial-of-service attack due to an unauthenticated attacker being able to send a truncated quoted argument, leading to an infinite CPU loop. This can result in significant degradation of service for Sieve script management, potentially exhausting server resources. Organizations utilizing ManageSieve should prioritize this vulnerability by monitoring CPU usage, restricting access to trusted clients, and ensuring they are running a patched version of the software.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-40019
Severity
MEDIUM
CVSS
5.9
EPSS
0.32%

Original NVD Description

An unauthenticated attacker can send a truncated quoted argument to the ManageSieve login process, which makes it spin in an infinite loop consuming CPU. This can cause degradation or denial of service for Sieve script management, and repeated connections can consume all available CPU on the server. Monitor system for abnormal CPU usage and kill the offending process. Restrict network access to the ManageSieve service to trusted clients. Update to non-vulnerable version. No publicly available exploits are known.