Impact
Cyrus IMAP (cyrus-imapd) contains a flaw where the LOCALDELETE command bypasses normal access control checks, allowing an authenticated user who is not an administrator to delete any mailbox. The vulnerability is identified as an authorization bypass and is classified under CWE-266 and CWE-863. If exploited, this flaw permits a non‑admin user to strip mailboxes from the server, causing loss of data and potentially disrupting service for other users.
Affected Systems
The affected software is Cyrus IMAP through version 3.12.2. The product is named Cyrus IMAP and is maintained by the cyrusimap vendor. All installations running 3.12.2 or earlier are susceptible; the vendor released a patch in the 3.12.3 release notes.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, and the EPSS score is less than 1 %, suggesting a low probability of exploitation in the wild. The flaw is not listed in the CISA KEV catalog, meaning it has not been observed in many known attacks. Exploitation requires only local authentication and the ability to issue IMAP commands, so an attacker with access to a valid user account on the server could simply run LOCALDELETE and delete arbitrary mailboxes.
OpenCVE Enrichment