Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-47087

Опубликовано: 16 июл. 2026
Источник: redhat
CVSS3: 3.5

Описание

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH does not honor revoked authorizer access. A URLAUTH URL minted while the authorizer had access continued to work after that access was revoked.

A flaw was found in Cyrus IMAP. The URLAUTH mechanism in Cyrus IMAP through version 3.12.2 does not properly revoke access for an authorizer. This allows a previously authorized user to retain access via a URLAUTH URL, even after their authorization has been revoked, potentially leading to unauthorized information disclosure.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10cyrus-imapdUnder investigation
Red Hat Enterprise Linux 6cyrus-imapdUnder investigation
Red Hat Enterprise Linux 7cyrus-imapdUnder investigation
Red Hat Enterprise Linux 8cyrus-imapdUnder investigation
Red Hat Enterprise Linux 9cyrus-imapdUnder investigation

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-613
https://bugzilla.redhat.com/show_bug.cgi?id=2501459cyrus-imapd: Cyrus IMAP: Unauthorized access due to URLAUTH not honoring revoked authorizer access

3.5 Low

CVSS3

Связанные уязвимости

CVSS3: 3.5
ubuntu
21 день назад

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH does not honor revoked authorizer access. A URLAUTH URL minted while the authorizer had access continued to work after that access was revoked.

CVSS3: 3.5
nvd
21 день назад

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH does not honor revoked authorizer access. A URLAUTH URL minted while the authorizer had access continued to work after that access was revoked.

CVSS3: 3.5
debian
21 день назад

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. U ...

CVSS3: 3.5
github
21 день назад

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH does not honor revoked authorizer access. A URLAUTH URL minted while the authorizer had access continued to work after that access was revoked.

suse-cvrf
20 дней назад

Security update for cyrus-imapd

3.5 Low

CVSS3