PT-2026-60550 · Unknown · Cyrus Imap
CVE-2026-47082
·
Published
2026-07-16
·
Updated
2026-07-20
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Cyrus IMAP versions prior to 3.12.3
Description
An issue exists in the vacation "fcc" feature of cyrus-imapd. This feature, used to save a copy of a sent message via a Sieve script, fails to check the destination-mailbox Access Control List (ACL). Consequently, a user can deliver vacation auto-reply copies into any specified mailbox, bypassing the requirement for insert permissions on the destination mailbox.
Recommendations
Update Cyrus IMAP to version 3.12.3 or later.
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cyrus Imap