Impact
The vulnerability allows an attacker to forge a URLAUTH token in Cyrus IMAP by computing an HMAC‑SHA1 value with a predictable key. The missing mboxkey protection in versions up to 3.12.2 enables this forgery, giving the attacker read access to any mailbox whose folder name they know and for which no authentication URL has been issued, resulting in unauthorized disclosure of mailbox contents. The weakness corresponds to CWE‑340 and CWE‑341.
Affected Systems
Cyrus IMAP servers running any release through 3.12.2 are impacted. Versions 3.12.3 and later include a fix that restores the missing mboxkey check. No other vendors or products are listed as affected.
Risk and Exploitability
The CVSS score of 4.0 indicates low severity, while an EPSS score of less than 1% suggests a very low likelihood of exploitation. URLAUTH is an obscure feature, and discovery requires knowledge of a folder name that has never had an auth URL issued, further reducing risk. The vulnerability is not included in CISA's KEV catalog, and to date no public exploits have been documented.
OpenCVE Enrichment