Junglewise Threat Intelligence

CVE-2026-47085: Cyrus IMAP URLAUTH token forgery via missing mboxkey

CVE-2026-47085 · Severity: medium · CVSS 4 · Published 2026-07-16

Vendors: Cyrus.

Executive brief

Cyrus IMAP, a widely used email server, contains a vulnerability in an obscure feature called URLAUTH. If an attacker knows the name of a specific folder in a user's account that has never used this feature, they can bypass security checks to read the contents of that mailbox. While the impact is a loss of data privacy, the risk is considered low because the affected feature is rarely used by modern email software.

Technical details

A vulnerability in cyrus-imapd (through version 3.12.2) stems from the generation of predictable identifiers (CWE-340) within the URLAUTH feature. When a victim has never issued an auth URL for a specific folder, the 'mboxkey' is missing, leading the server to use a predictable value. An attacker who knows the target folder name can compute a valid HMAC-SHA1 token, effectively forging a URLAUTH token. This allows the attacker to bypass access controls and gain read-only access to the mailbox contents via the network without prior authentication. The issue is mitigated by the fact that URLAUTH is an infrequently used IMAP extension. A fix is available in version 3.12.3.

Affected products

  • Cyrus Cyrus IMAP through 3.12.2

Timeline

  • 2026-07-16: advisory: NVD publication date
  • 2026-07-16: patched: Fixed in Cyrus IMAP 3.12.3

References