Junglewise Threat Intelligence

CVE-2026-61907: Cyrus IMAP JMAP snooze ACL bypass

CVE-2026-61907 · Severity: medium · CVSS 4.3 · Published 2026-09-09

Vendors: Cyrus.

Executive brief

Cyrus IMAP is an email and calendar server used by universities and enterprises. An authenticated user with limited permissions to another user's snoozed mailbox could bypass access controls to insert email into that user's inbox or other mailboxes, potentially allowing unauthorized delivery of messages or access to another user's mail folders.

Technical details

The vulnerability exists in Cyrus IMAP's JMAP snooze implementation, which fails to properly enforce destination-mailbox access control lists (ACLs). An authenticated user with only insert permissions on another user's snoozed mailbox can craft a JMAP request to insert mail into the target user's inbox or other mailboxes whose ID is known, despite lacking insert permissions to those target mailboxes. The root cause is insufficient ACL validation in the JMAP snooze operation. The attack requires authentication but no special privileges beyond having basic mailbox access. The vulnerability was patched in Cyrus IMAP 3.12.4 and earlier versions.

Affected products

  • Cyrus IMAP before 3.12.4

Timeline

  • 2026-09-09: disclosed
  • 2026: patched: Fixed in Cyrus IMAP 3.12.4

References