Executive brief
Cyrus IMAP is an email, contacts, and calendar server used in production environments globally. An authenticated user with partial access to another user's calendar or address book can read unshared events and contacts by exploiting a flaw in the multiget REPORT feature, potentially exposing sensitive schedule and contact information despite access restrictions.
Technical details
The vulnerability is an access control list (ACL) bypass in the CalDAV/CardDAV multiget REPORT handler. An authenticated DAV user with delegated access to another user's calendar or address book can circumvent per-href ACL checks by including target hrefs in a calendar-multiget or addressbook-multiget REPORT request, allowing them to read events or contacts that were not explicitly shared with them. The attack requires existing authenticated DAV access and network reachability to the Cyrus IMAP server. The vulnerability is fixed in Cyrus IMAP 3.12.4 and later versions.
Affected products
- Cyrus IMAP before 3.12.4
Timeline
- 2026-09-09: disclosed