Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-47083

Опубликовано: 16 июл. 2026
Источник: redhat
CVSS3: 4.3

Описание

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an ESEARCH cross-user content oracle. By using the ESEARCH command, an authenticated IMAP user could enumerate folder names under any account they could name. Search would return UIDs of messages matching the search, creating a content oracle (without allowing arbitrary reads of the target's content).

A flaw was found in Cyrus IMAP. An authenticated user can exploit the ESEARCH command to discover the existence of folder names belonging to other user accounts. This vulnerability leads to information disclosure, allowing an attacker to gain unauthorized knowledge about the structure of other users' mailboxes.

Отчет

This Moderate impact information disclosure flaw in Cyrus IMAP allows an authenticated user to enumerate folder names belonging to other accounts via the ESEARCH command. While it does not permit arbitrary content reads, this vulnerability could expose the structure of other users' mailboxes, potentially aiding further reconnaissance.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10cyrus-imapdUnder investigation
Red Hat Enterprise Linux 6cyrus-imapdOut of support scope
Red Hat Enterprise Linux 7cyrus-imapdOut of support scope
Red Hat Enterprise Linux 8cyrus-imapdFix deferred
Red Hat Enterprise Linux 9cyrus-imapdUnder investigation

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-201
https://bugzilla.redhat.com/show_bug.cgi?id=2501451cyrus-imapd: Cyrus IMAP: Information disclosure via ESEARCH command

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
ubuntu
21 день назад

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an ESEARCH cross-user content oracle. By using the ESEARCH command, an authenticated IMAP user could enumerate folder names under any account they could name. Search would return UIDs of messages matching the search, creating a content oracle (without allowing arbitrary reads of the target's content).

CVSS3: 4.3
nvd
21 день назад

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an ESEARCH cross-user content oracle. By using the ESEARCH command, an authenticated IMAP user could enumerate folder names under any account they could name. Search would return UIDs of messages matching the search, creating a content oracle (without allowing arbitrary reads of the target's content).

CVSS3: 4.3
debian
21 день назад

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. T ...

CVSS3: 4.3
github
21 день назад

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an ESEARCH cross-user content oracle. By using the ESEARCH command, an authenticated IMAP user could enumerate folder names under any account they could name. Search would return UIDs of messages matching the search, creating a content oracle (without allowing arbitrary reads of the target's content).

suse-cvrf
20 дней назад

Security update for cyrus-imapd

4.3 Medium

CVSS3