Junglewise Threat Intelligence

CVE-2026-47086: Cyrus IMAP ACL bypass via GENURLAUTH tokens

CVE-2026-47086 · Severity: low · CVSS 3.5 · Published 2026-07-16

Vendors: Cyrus.

Executive brief

Cyrus IMAP is a widely used mail server for managing and accessing email. A security flaw allows any logged-in user to bypass access controls and read emails from other users' mailboxes. This could lead to the unauthorized exposure of sensitive communications and private data across the organization.

Technical details

An incorrect authorization vulnerability (CWE-863) exists in cyrus-imapd through version 3.12.2. The GENURLAUTH command fails to properly validate permissions when issuing tokens. An authenticated attacker can 'mint' a URLAUTH token for any mailbox they can name, even if they lack read access. This token can then be used to bypass ACLs and retrieve message content. The issue is addressed in version 3.12.3.

Affected products

  • Cyrus Cyrus IMAP through 3.12.2

Timeline

  • 2026-07-16: disclosed
  • 2026-07-16: advisory
  • 2026-07-16: patched: Fixed in version 3.12.3

References