CVE-2026-61909 PUBLISHED

Assigner: mitre
Reserved: 13.07.2026 Published: 09.09.2026 Updated: 09.09.2026

An issue was discovered in Cyrus IMAP before 3.12.4. CalDAV/CardDAV multiget bypasses a per-href ACL. An authenticated DAV user with some shared access to another user's calendar or address book could read even unshared events or contacts by including the target hrefs in a calendar-multiget or addressbook-multiget REPORT.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N
CVSS Score: 3.5

Product Status

Vendor cyrusimap
Product Cyrus IMAP
Versions Default: unaffected
  • affected from 0 to 3.8.8 (excl.)
  • affected from 3.9.0 to 3.10.4 (excl.)
  • affected from 3.11.0 to 3.12.4 (excl.)

References

Problem Types

  • CWE-420 Unprotected Alternate Channel CWE