Executive brief
Cyrus IMAP is an email and calendar server used in production environments worldwide. An authenticated user can exploit a flaw in Sieve mail filtering to probe whether other users' private mailboxes exist or read shared mailbox settings by observing how mail delivery behaves, potentially exposing sensitive organizational structure information.
Technical details
The vulnerability is an information disclosure flaw in Cyrus IMAP's Sieve mail filtering implementation. An authenticated user can craft a Sieve script with fileinto branches to different mailbox names and observe which branch fires during LMTP delivery, allowing them to deduce whether another user's private mailbox exists or read shared mailbox annotations. The attack requires authentication but no special privileges beyond the ability to install Sieve scripts. An attacker can map out the mailbox structure and shared configuration of other users. The vulnerability was fixed in version 3.12.4.
Affected products
- Cyrus IMAP before 3.12.4
Timeline
- 2026-09-09: disclosed