CVE-2026-61907
CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th
An issue was discovered in Cyrus IMAP before 3.12.4. JMAP snooze bypasses the destination-mailbox ACL. An authenticated user with insert permissions on another user's snoozed mailbox could cause insertion of mail to that user's inbox, or any other of their mailboxes whose id was known to the user, despite having no insert permissions to the target mailbox.
| CWE | CWE-863 |
| Vendor | cyrusimap |
| Product | cyrus imap |
| Published | Sep 9, 2026 |
| Last Updated | Sep 14, 2026 |
Stay Ahead of the Next One
Get instant alerts for cyrusimap cyrus imap
Be the first to know when new medium vulnerabilities affecting cyrusimap cyrus imap are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
None
Affected Versions
cyrusimap / Cyrus IMAP
0 < 3.8.8 3.9.0 < 3.10.4 3.11.0 < 3.12.4
References
cyrusimap.org: https://cyrusimap.org cyrusimap.org: https://www.cyrusimap.org/3.12/imap/download/release-notes/3.12/x/3.12.4.html cyrusimap.org: https://www.cyrusimap.org/3.12/imap/download/release-notes/3.10/x/3.10.4.html cyrusimap.org: https://www.cyrusimap.org/3.12/imap/download/release-notes/3.8/x/3.8.8.html