PT-2026-60549 · Cyrusimap+3 · Cyrus Imap
CVE-2026-47081
·
Published
2026-07-16
·
Updated
2026-07-17
CVSS v3.1
3.1
Low
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
cyrus-imapd versions prior to 3.12.3
Description
An authenticated IMAP user can probe for the existence of arbitrary mailboxes on other users' accounts using the
XAPPLEPUSHSERVICE command. This folder existence oracle allows the user to hijack push notifications by creating Apple Push Notification Service notifications for new mail in those mailboxes to their own APNS device. This issue does not leak mailbox content; instead, it triggers a notice that the mailbox has changed whenever the modseq changes.Recommendations
Update to a version newer than 3.12.2.
As a temporary mitigation, restrict the use of the
XAPPLEPUSHSERVICE command.Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cyrus Imap