4.3
CVE-2026-61911
- EPSS 0.22%
- Veröffentlicht 09.09.2026 00:00:00
- Zuletzt bearbeitet 16.09.2026 15:23:58
- Erkennungen
An issue was discovered in Cyrus IMAP before 3.12.4. There is a Sieve mailbox existence oracle. An authenticated user could install a Sieve script that probed whether another user's private mailbox existed, or read the value of shared mailbox annotations, by observing which fileinto branch fired during LMTP delivery.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.22% | 0.121 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| MITRE | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
CWE-497 Exposure of Sensitive System Information to an Unauthorized Control Sphere
The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does.
https://cyrusimap.org
https://www.cyrusimap.org/3.12/imap/download/release-notes/3.12/x/3.12.4.html
https://www.cyrusimap.org/3.12/imap/download/release-notes/3.10/x/3.10.4.html
https://www.cyrusimap.org/3.12/imap/download/release-notes/3.8/x/3.8.8.html