CVE-2026-61911 PUBLISHED

Assigner: mitre
Reserved: 13.07.2026 Published: 09.09.2026 Updated: 09.09.2026

An issue was discovered in Cyrus IMAP before 3.12.4. There is a Sieve mailbox existence oracle. An authenticated user could install a Sieve script that probed whether another user's private mailbox existed, or read the value of shared mailbox annotations, by observing which fileinto branch fired during LMTP delivery.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS Score: 4.3

Product Status

Vendor cyrusimap
Product Cyrus IMAP
Versions Default: unaffected
  • affected from 0 to 3.8.8 (excl.)
  • affected from 3.9.0 to 3.10.4 (excl.)
  • affected from 3.11.0 to 3.12.4 (excl.)

References

Problem Types

  • CWE-497 Exposure of Sensitive System Information to an Unauthorized Control Sphere CWE