4.3
CVE-2026-61907
- EPSS 0.35%
- Veröffentlicht 09.09.2026 00:00:00
- Zuletzt bearbeitet 14.09.2026 16:17:17
- Erkennungen
An issue was discovered in Cyrus IMAP before 3.12.4. JMAP snooze bypasses the destination-mailbox ACL. An authenticated user with insert permissions on another user's snoozed mailbox could cause insertion of mail to that user's inbox, or any other of their mailboxes whose id was known to the user, despite having no insert permissions to the target mailbox.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellercyrusimap
≫
Produkt
Cyrus IMAP
Default Statusunaffected
Version
0
Version <
3.8.8
Status
affected
Version
3.9.0
Version <
3.10.4
Status
affected
Version
3.11.0
Version <
3.12.4
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.35% | 0.282 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| MITRE | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
|
CWE-863 Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
https://cyrusimap.org
https://www.cyrusimap.org/3.12/imap/download/release-notes/3.12/x/3.12.4.html
https://www.cyrusimap.org/3.12/imap/download/release-notes/3.10/x/3.10.4.html
https://www.cyrusimap.org/3.12/imap/download/release-notes/3.8/x/3.8.8.html