Executive brief
Cyrus IMAP is a widely used mail server for managing and accessing email. A security flaw allows any logged-in user to bypass access controls and read emails from other users' mailboxes. This could lead to the unauthorized exposure of sensitive communications and private data across the organization.
Technical details
An incorrect authorization vulnerability (CWE-863) exists in cyrus-imapd through version 3.12.2. The GENURLAUTH command fails to properly validate permissions when issuing tokens. An authenticated attacker can 'mint' a URLAUTH token for any mailbox they can name, even if they lack read access. This token can then be used to bypass ACLs and retrieve message content. The issue is addressed in version 3.12.3.
Affected products
- Cyrus Cyrus IMAP through 3.12.2
Timeline
- 2026-07-16: disclosed
- 2026-07-16: advisory
- 2026-07-16: patched: Fixed in version 3.12.3