Impact
The flaw lies in the IMAP LISTRIGHTS command, which should only be used by administrators on a mailbox; in affected versions any authenticated user could invoke LISTRIGHTS for any mailbox name they could supply, learning which principals had what level of access and representing an authorization bypass classified as CWE-266 and CWE-862.
Affected Systems
The vulnerability existed in Cyrus IMAP up through release 3.12.2; users running 3.12.0 to 3.12.2 are impacted, and the issue was fixed in 3.12.3, so servers still on 3.12.2 or earlier remain susceptible.
Risk and Exploitability
The CVSS score of 4.3 indicates low‑to‑moderate severity, and an EPSS of <1% implies a very low exploitation probability; because the flaw requires an authenticated account, an attacker who compromises a user credential can easily retrieve additional mailbox permission information; the vulnerability is not listed in CISA’s KEV catalog and no public exploits have been documented, so overall risk is moderate, weighed against the low exploitation likelihood but the potential to expose internal access hierarchies.
OpenCVE Enrichment