
CVE-2026-27855 Dovecot OTP authentication is vulnerable to replay attack under specific conditions. If auth cache is enabled, and username is altered in passdb, then OTP credentials… https://www.cve.org/CVERecord?id=CVE-2026-27855
Post summary
The entry announces a replay attack vulnerability in Dovecot OTP under specific conditions, but does not provide a PoC, exploit tool, patch, or evidence of active exploitation.
