Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-47086

Опубликовано: 16 июл. 2026
Источник: redhat
CVSS3: 4.3
EPSS Низкий

Описание

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. GENURLAUTH-issued tokens can bypass ACLs. Any authenticated user could mint a URLAUTH token (via the GENURLAUTH command) for any mailbox they could name, even without read access on it. This would allow reading mail from mailboxes despite having no granted permissions.

A flaw was found in cyrus-imapd. An authenticated user could exploit this vulnerability by minting a URLAUTH token through the GENURLAUTH command. This allows bypassing Access Control Lists (ACLs), which are rules that control access to mailboxes. Consequently, an attacker could read mail from any mailbox, even without having been granted explicit read permissions.

Отчет

This flaw in cyrus-imapd allows an authenticated attacker to bypass Access Control Lists (ACLs) by minting a URLAUTH token via the GENURLAUTH command. This enables unauthorized reading of mail from any mailbox, even without explicit read permissions, posing a significant risk to data confidentiality in Red Hat deployments utilizing the Cyrus IMAP server.

Меры по смягчению последствий

To reduce the attack surface, restrict network access to the Cyrus IMAP server to only trusted clients and networks by configuring appropriate firewall rules. If the Cyrus IMAP service is not essential, consider disabling it. To disable the cyrus-imapd service, execute sudo systemctl stop cyrus-imapd and sudo systemctl disable cyrus-imapd. Disabling the service will prevent all mail access via IMAP and may require a system restart to fully take effect.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10cyrus-imapdFix deferred
Red Hat Enterprise Linux 6cyrus-imapdOut of support scope
Red Hat Enterprise Linux 7cyrus-imapdOut of support scope
Red Hat Enterprise Linux 8cyrus-imapdFix deferred
Red Hat Enterprise Linux 9cyrus-imapdFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-639
https://bugzilla.redhat.com/show_bug.cgi?id=2501461cyrus-imapd: cyrus-imapd: Information disclosure via URLAUTH token bypass of Access Control Lists

EPSS

Процентиль: 8%
0.00179
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 3.5
ubuntu
21 день назад

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. GENURLAUTH-issued tokens can bypass ACLs. Any authenticated user could mint a URLAUTH token (via the GENURLAUTH command) for any mailbox they could name, even without read access on it. This would allow reading mail from mailboxes despite having no granted permissions.

CVSS3: 3.5
nvd
21 день назад

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. GENURLAUTH-issued tokens can bypass ACLs. Any authenticated user could mint a URLAUTH token (via the GENURLAUTH command) for any mailbox they could name, even without read access on it. This would allow reading mail from mailboxes despite having no granted permissions.

CVSS3: 3.5
debian
21 день назад

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. G ...

CVSS3: 3.5
github
21 день назад

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. GENURLAUTH-issued tokens can bypass ACLs. Any authenticated user could mint a URLAUTH token (via the GENURLAUTH command) for any mailbox they could name, even without read access on it. This would allow reading mail from mailboxes despite having no granted permissions.

suse-cvrf
20 дней назад

Security update for cyrus-imapd

EPSS

Процентиль: 8%
0.00179
Низкий

4.3 Medium

CVSS3