Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-47085

Опубликовано: 16 июл. 2026
Источник: redhat
CVSS3: 4

Описание

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH token forgery can occur via a missing mboxkey. If an attacker knew a folder name on the victim's account for which the victim had never issued an auth URL, they could forge a working URLAUTH token by computing an HMAC-SHA1 value with a predictable key, giving them read access to the mailbox. (URLAUTH is an obscure feature, meaning that the odds of any user actually being susceptible to this attack are very low. Perhaps no public clients use URLAUTH.)

A flaw was found in Cyrus IMAP (cyrus-imapd). A remote attacker could exploit a vulnerability related to URLAUTH token forgery, caused by a missing mailbox key. This could allow the attacker to gain unauthorized read access to a victim's mailbox. The likelihood of exploitation is low due to the obscurity of the URLAUTH feature.

Отчет

Moderate: A flaw in Cyrus IMAP (cyrus-imapd) allows for URLAUTH token forgery due to a missing mailbox key, potentially granting a remote attacker unauthorized read access to a victim's mailbox. The impact is limited as the URLAUTH feature is obscure and rarely used, significantly reducing the likelihood of exploitation in typical Red Hat deployments.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10cyrus-imapdUnder investigation
Red Hat Enterprise Linux 6cyrus-imapdOut of support scope
Red Hat Enterprise Linux 7cyrus-imapdOut of support scope
Red Hat Enterprise Linux 8cyrus-imapdFix deferred
Red Hat Enterprise Linux 9cyrus-imapdUnder investigation

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-341
https://bugzilla.redhat.com/show_bug.cgi?id=2501446cyrus-imapd: Cyrus IMAP: Information disclosure via URLAUTH token forgery

4 Medium

CVSS3

Связанные уязвимости

CVSS3: 4
ubuntu
21 день назад

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH token forgery can occur via a missing mboxkey. If an attacker knew a folder name on the victim's account for which the victim had never issued an auth URL, they could forge a working URLAUTH token by computing an HMAC-SHA1 value with a predictable key, giving them read access to the mailbox. (URLAUTH is an obscure feature, meaning that the odds of any user actually being susceptible to this attack are very low. Perhaps no public clients use URLAUTH.)

CVSS3: 4
nvd
21 день назад

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH token forgery can occur via a missing mboxkey. If an attacker knew a folder name on the victim's account for which the victim had never issued an auth URL, they could forge a working URLAUTH token by computing an HMAC-SHA1 value with a predictable key, giving them read access to the mailbox. (URLAUTH is an obscure feature, meaning that the odds of any user actually being susceptible to this attack are very low. Perhaps no public clients use URLAUTH.)

CVSS3: 4
debian
21 день назад

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. U ...

CVSS3: 4
github
21 день назад

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH token forgery can occur via a missing mboxkey. If an attacker knew a folder name on the victim's account for which the victim had never issued an auth URL, they could forge a working URLAUTH token by computing an HMAC-SHA1 value with a predictable key, giving them read access to the mailbox. (URLAUTH is an obscure feature, meaning that the odds of any user actually being susceptible to this attack are very low. Perhaps no public clients use URLAUTH.)

suse-cvrf
20 дней назад

Security update for cyrus-imapd

4 Medium

CVSS3