PT-2026-60551 · Unknown · Cyrus Imap
CVE-2026-47083
·
Published
2026-07-16
·
Updated
2026-07-20
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
cyrus-imapd versions prior to 3.12.3
Description
An authenticated IMAP user can utilize the ESEARCH command to enumerate folder names under any specified account. This creates a content oracle, where the search returns UIDs of messages that match the search criteria, allowing the user to verify the existence of specific content without granting arbitrary read access to the target content.
Recommendations
Update cyrus-imapd to version 3.12.3 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cyrus Imap