Impact
An ACL bypass flaw exists in the vacation \"fcc\" feature of Cyrus IMAP. When a user’s vacation Sieve script contains a :fcc clause, the server skips the ACL check for the destination mailbox. This allows the script to write copies of auto‑replies into any mailbox that can be named, even when the script owner has no insert permission. The flaw leads to unauthorized data placement and potential disclosure of mailbox content, but it does not provide code execution or privilege escalation beyond mailbox write capability.
Affected Systems
The vulnerability affects all Cyrus IMAP releases up to and including 3.12.2. Users running Cyrus IMAP on those versions are susceptible. Versions 3.12.3 and later contain the fix.
Risk and Exploitability
The CVSS score of 5.4 classifies the flaw as moderate. The EPSS score is below 1 %, indicating a low probability of exploitation in the wild, and it is not listed in the CISA KEV catalog. The most likely attack vector is through a user’s own vacation Sieve script; a compromised or malicious user can craft a :fcc clause to write to another mailbox. While the exploit requires only legitimate access to a user account with vacation script configuration rights, it permits unauthorized writes that could tamper or expose data.
OpenCVE Enrichment