Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-47089

Опубликовано: 16 июл. 2026
Источник: redhat
CVSS3: 4.3
EPSS Низкий

Описание

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. LISTRIGHTS os not limited to users with admin access. An authenticated user could call IMAP LISTRIGHTS against any mailbox they could name and learn what principals had what access to it. (This action should have been restricted to users with admin access on the target mailbox.)

A flaw was found in Cyrus IMAP (cyrus-imapd). An authenticated user can exploit this vulnerability by using the IMAP LISTRIGHTS command. This allows the user to learn the access permissions of any mailbox they can name, which should be restricted to administrators. This leads to unauthorized information disclosure regarding mailbox access controls.

Отчет

This Moderate-impact information disclosure flaw in Cyrus IMAP allows an authenticated user to enumerate mailbox access rights via the LISTRIGHTS command. While requiring prior authentication, this bypasses intended administrative restrictions, potentially exposing sensitive access control configurations within a Red Hat deployment. The impact is limited to information disclosure and does not grant further privileges or data modification.

Меры по смягчению последствий

To mitigate this issue, restrict network access to the Cyrus IMAP service to only trusted clients and networks. This can be achieved by configuring firewall rules to limit inbound connections to the IMAP port (typically 143 for IMAP and 993 for IMAPS) on the server hosting cyrus-imapd. Additionally, ensure that only necessary users have authenticated access to the IMAP server.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10cyrus-imapdFix deferred
Red Hat Enterprise Linux 6cyrus-imapdOut of support scope
Red Hat Enterprise Linux 7cyrus-imapdOut of support scope
Red Hat Enterprise Linux 8cyrus-imapdFix deferred
Red Hat Enterprise Linux 9cyrus-imapdFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-266
https://bugzilla.redhat.com/show_bug.cgi?id=2501456cyrus-imapd: Cyrus IMAP: Information disclosure via LISTRIGHTS

EPSS

Процентиль: 8%
0.00178
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
ubuntu
21 день назад

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. LISTRIGHTS os not limited to users with admin access. An authenticated user could call IMAP LISTRIGHTS against any mailbox they could name and learn what principals had what access to it. (This action should have been restricted to users with admin access on the target mailbox.)

CVSS3: 4.3
nvd
21 день назад

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. LISTRIGHTS os not limited to users with admin access. An authenticated user could call IMAP LISTRIGHTS against any mailbox they could name and learn what principals had what access to it. (This action should have been restricted to users with admin access on the target mailbox.)

CVSS3: 4.3
debian
21 день назад

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. L ...

CVSS3: 4.3
github
21 день назад

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. LISTRIGHTS os not limited to users with admin access. An authenticated user could call IMAP LISTRIGHTS against any mailbox they could name and learn what principals had what access to it. (This action should have been restricted to users with admin access on the target mailbox.)

suse-cvrf
20 дней назад

Security update for cyrus-imapd

EPSS

Процентиль: 8%
0.00178
Низкий

4.3 Medium

CVSS3