CVE-2026-61915
- EPSS 0.22%
- Veröffentlicht 09.09.2026 00:00:00
- Zuletzt bearbeitet 16.09.2026 15:23:51
An issue was discovered in Cyrus IMAP before 3.12.4. There is a VPATCH BYPARAM double-free. An authenticated calendar user could crash a Cyrus CalDAV worker with a PATCH containing PATCH-ACTION="BYPARAM@..." against a resource with two or more proper...
CVE-2026-61911
- EPSS 0.22%
- Veröffentlicht 09.09.2026 00:00:00
- Zuletzt bearbeitet 16.09.2026 15:23:58
An issue was discovered in Cyrus IMAP before 3.12.4. There is a Sieve mailbox existence oracle. An authenticated user could install a Sieve script that probed whether another user's private mailbox existed, or read the value of shared mailbox annotat...
- EPSS 0.19%
- Veröffentlicht 09.09.2026 00:00:00
- Zuletzt bearbeitet 16.09.2026 15:24:04
An issue was discovered in Cyrus IMAP before 3.12.4. Mailbox/set let a sharee change a special-use role on shared mailboxes. An authenticated user with maySetKeywords on another user's mailbox could change that mailbox's specialuse annotation. This c...
CVE-2026-61909
- EPSS 0.2%
- Veröffentlicht 09.09.2026 00:00:00
- Zuletzt bearbeitet 16.09.2026 15:24:24
An issue was discovered in Cyrus IMAP before 3.12.4. CalDAV/CardDAV multiget bypasses a per-href ACL. An authenticated DAV user with some shared access to another user's calendar or address book could read even unshared events or contacts by includin...
CVE-2026-61908
- EPSS 0.21%
- Veröffentlicht 09.09.2026 00:00:00
- Zuletzt bearbeitet 16.09.2026 15:24:33
An issue was discovered in Cyrus IMAP before 3.12.4. A JMAP email-header blob ID can reference an out-of-bounds index. An authenticated user could attempt to download a crafted JMAP blob ID of the form H<emailid>-<index>, which could read past the en...
CVE-2026-61907
- EPSS 0.35%
- Veröffentlicht 09.09.2026 00:00:00
- Zuletzt bearbeitet 14.09.2026 16:17:17
An issue was discovered in Cyrus IMAP before 3.12.4. JMAP snooze bypasses the destination-mailbox ACL. An authenticated user with insert permissions on another user's snoozed mailbox could cause insertion of mail to that user's inbox, or any other of...
CVE-2026-47087
- EPSS 0.19%
- Veröffentlicht 16.07.2026 00:00:00
- Zuletzt bearbeitet 17.07.2026 18:04:04
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH does not honor revoked authorizer access. A URLAUTH URL minted while the authorizer had access continued to work after that access was revoked.
CVE-2026-47089
- EPSS 0.18%
- Veröffentlicht 16.07.2026 00:00:00
- Zuletzt bearbeitet 17.07.2026 18:04:04
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. LISTRIGHTS os not limited to users with admin access. An authenticated user could call IMAP LISTRIGHTS against any mailbox they could name and learn what principals had what access ...
CVE-2026-47088
- EPSS 0.18%
- Veröffentlicht 16.07.2026 00:00:00
- Zuletzt bearbeitet 17.07.2026 18:04:04
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is heap exposure in nested MIME comment parsing. An authenticated IMAP user could craft an email message containing an RFC 822 comment ending with a backslash. When parsing th...
CVE-2026-47086
- EPSS 0.18%
- Veröffentlicht 16.07.2026 00:00:00
- Zuletzt bearbeitet 17.07.2026 18:04:04
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. GENURLAUTH-issued tokens can bypass ACLs. Any authenticated user could mint a URLAUTH token (via the GENURLAUTH command) for any mailbox they could name, even without read access on...