Junglewise Threat Intelligence

CVE-2026-61910: Cyrus IMAP privilege escalation in Mailbox/set

CVE-2026-61910 · Severity: low · CVSS 3.5 · Published 2026-09-09

Vendors: Cyrus.

Executive brief

Cyrus IMAP is an email and calendar server used to manage mailboxes for organizations. An authenticated user who has limited keyword-setting permissions on another user's shared mailbox can change that mailbox's special-use role (such as marking it as archived or snoozed). This could cause mail to be incorrectly routed to the shared mailbox, potentially exposing more content than the mailbox owner intended to share.

Technical details

A privilege escalation vulnerability exists in Cyrus IMAP before 3.12.4 in the Mailbox/set functionality. An authenticated user with maySetKeywords permission on another user's mailbox can modify the specialuse annotation attribute, allowing them to change the mailbox's role to archived, snoozed, or other roles. The vulnerability requires existing authentication and limited permissions on the target mailbox (maySetKeywords). An attacker can exploit this to alter mailbox behavior and cause unintended mail delivery routing. The vulnerability is mitigated in cases where the target user already has a non-shared mailbox with the same role, as role duplication suppression prevents the update. The fix is available in Cyrus IMAP 3.12.4 and later versions.

Affected products

  • Cyrus IMAP before 3.12.4

Timeline

  • 2026-09-09: disclosed

References