Junglewise Threat Intelligence

CVE-2026-47084: Cyrus IMAP authorization bypass in LOCALDELETE command

CVE-2026-47084 · Severity: medium · CVSS 6.5 · Published 2026-07-16

Vendors: Cyrus.

Executive brief

A vulnerability has been identified in Cyrus IMAP, a widely used email server, where certain administrative commands do not properly check user permissions. This allows a standard email user to delete mailboxes belonging to other users or the system, even if they do not have administrative rights. Such an exploit could lead to significant data loss and disruption of email services.

Technical details

An incorrect authorization vulnerability (CWE-863) exists in the LOCALDELETE IMAP command of cyrus-imapd. The root cause is a failure to perform Access Control List (ACL) validation when this specific command is invoked. An authenticated but non-privileged attacker can send a specially crafted IMAP command to the server to delete mailboxes they do not own and for which they lack administrative permissions. This bypasses the intended restriction that LOCALDELETE should be an admin-only operation. The issue is resolved in Cyrus IMAP version 3.12.3.

Affected products

  • Cyrus Cyrus IMAP through 3.12.2

Timeline

  • 2026-07-16: disclosed
  • 2026-07-16: advisory
  • 2026-07-16: patched: Fixed in version 3.12.3

References