Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-61907

Опубликовано: 09 сент. 2026
Источник: redhat
CVSS3: 4.3

Описание

An issue was discovered in Cyrus IMAP before 3.12.4. JMAP snooze bypasses the destination-mailbox ACL. An authenticated user with insert permissions on another user's snoozed mailbox could cause insertion of mail to that user's inbox, or any other of their mailboxes whose id was known to the user, despite having no insert permissions to the target mailbox.

A flaw was found in cyrus-imapd. An authenticated user with insert permissions on another user's snoozed mailbox could bypass access controls. This allows the user to insert mail into the target user's inbox or other known mailboxes, even without explicit insert permissions for those mailboxes. This vulnerability leads to unauthorized modification of another user's mail data.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10cyrus-imapdFix deferred
Red Hat Enterprise Linux 6cyrus-imapdOut of support scope
Red Hat Enterprise Linux 7cyrus-imapdFix deferred
Red Hat Enterprise Linux 8cyrus-imapdFix deferred
Red Hat Enterprise Linux 9cyrus-imapdFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-863
https://bugzilla.redhat.com/show_bug.cgi?id=2526303cyrus-imapd: cyrus-imapd: JMAP snooze bypasses destination-mailbox ACL

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
ubuntu
9 дней назад

An issue was discovered in Cyrus IMAP before 3.12.4. JMAP snooze bypasses the destination-mailbox ACL. An authenticated user with insert permissions on another user's snoozed mailbox could cause insertion of mail to that user's inbox, or any other of their mailboxes whose id was known to the user, despite having no insert permissions to the target mailbox.

CVSS3: 4.3
nvd
9 дней назад

An issue was discovered in Cyrus IMAP before 3.12.4. JMAP snooze bypasses the destination-mailbox ACL. An authenticated user with insert permissions on another user's snoozed mailbox could cause insertion of mail to that user's inbox, or any other of their mailboxes whose id was known to the user, despite having no insert permissions to the target mailbox.

CVSS3: 4.3
debian
9 дней назад

An issue was discovered in Cyrus IMAP before 3.12.4. JMAP snooze bypas ...

CVSS3: 4.3
github
9 дней назад

An issue was discovered in Cyrus IMAP before 3.12.4. JMAP snooze bypasses the destination-mailbox ACL. An authenticated user with insert permissions on another user's snoozed mailbox could cause insertion of mail to that user's inbox, or any other of their mailboxes whose id was known to the user, despite having no insert permissions to the target mailbox.

4.3 Medium

CVSS3