Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-47081

Опубликовано: 16 июл. 2026
Источник: redhat
CVSS3: 3.1
EPSS Низкий

Описание

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an XAPPLEPUSHSERVICE folder existence oracle and push hijack. An authenticated IMAP user could probe for the existence of arbitrary mailboxes on other users' accounts via the XAPPLEPUSHSERVICE command and then create Apple Push Notification Service notifications for new mail in those mailboxes to their own APNS device. This did not leak any data about the content of mailboxes. Instead, a "mailbox has changed" notice would be pushed when the mailbox modseq changed.

A flaw was found in Cyrus IMAP (cyrus-imapd). An authenticated user could exploit this vulnerability by using the XAPPLEPUSHSERVICE command to determine if specific mailboxes exist on other users' accounts. This could allow the attacker to create Apple Push Notification Service (APNS) notifications for these mailboxes, causing a "mailbox has changed" notice to be pushed to their own device when the mailbox is updated. While no content is leaked, this constitutes an information disclosure regarding the existence and activity of other users' mailboxes.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10cyrus-imapdFix deferred
Red Hat Enterprise Linux 6cyrus-imapdOut of support scope
Red Hat Enterprise Linux 7cyrus-imapdOut of support scope
Red Hat Enterprise Linux 8cyrus-imapdFix deferred
Red Hat Enterprise Linux 9cyrus-imapdFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-497
https://bugzilla.redhat.com/show_bug.cgi?id=2501453cyrus-imapd: Cyrus IMAP: Information disclosure of mailbox existence via XAPPLEPUSHSERVICE command

EPSS

Процентиль: 6%
0.00163
Низкий

3.1 Low

CVSS3

Связанные уязвимости

CVSS3: 3.1
ubuntu
21 день назад

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an XAPPLEPUSHSERVICE folder existence oracle and push hijack. An authenticated IMAP user could probe for the existence of arbitrary mailboxes on other users' accounts via the XAPPLEPUSHSERVICE command and then create Apple Push Notification Service notifications for new mail in those mailboxes to their own APNS device. This did not leak any data about the content of mailboxes. Instead, a "mailbox has changed" notice would be pushed when the mailbox modseq changed.

CVSS3: 3.1
nvd
21 день назад

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an XAPPLEPUSHSERVICE folder existence oracle and push hijack. An authenticated IMAP user could probe for the existence of arbitrary mailboxes on other users' accounts via the XAPPLEPUSHSERVICE command and then create Apple Push Notification Service notifications for new mail in those mailboxes to their own APNS device. This did not leak any data about the content of mailboxes. Instead, a "mailbox has changed" notice would be pushed when the mailbox modseq changed.

CVSS3: 3.1
debian
21 день назад

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. T ...

CVSS3: 3.1
github
21 день назад

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an XAPPLEPUSHSERVICE folder existence oracle and push hijack. An authenticated IMAP user could probe for the existence of arbitrary mailboxes on other users' accounts via the XAPPLEPUSHSERVICE command and then create Apple Push Notification Service notifications for new mail in those mailboxes to their own APNS device. This did not leak any data about the content of mailboxes. Instead, a "mailbox has changed" notice would be pushed when the mailbox modseq changed.

suse-cvrf
20 дней назад

Security update for cyrus-imapd

EPSS

Процентиль: 6%
0.00163
Низкий

3.1 Low

CVSS3