Description
An issue was discovered in Cyrus IMAP before 3.12.4. JMAP snooze bypasses the destination-mailbox ACL. An authenticated user with insert permissions on another user's snoozed mailbox could cause insertion of mail to that user's inbox, or any other of their mailboxes whose id was known to the user, despite having no insert permissions to the target mailbox.
Published: 2026-09-09
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Access Control Bypass
Action: Assess
AI Analysis

Impact

The vulnerability in Cyrus IMAP before version 3.12.4 allows an authenticated user with insert permissions on another user's snoozed mailbox to bypass destination‑mailbox ACL checks. By issuing a JMAP snooze command, the user can cause mail to be inserted into the target user's inbox or any other mailbox whose ID is known, even though that user has no insert permissions on the destination mailbox. This represents a serious authorization bypass, enabling an attacker to read, move, or tamper with messages in mailboxes they should not access.

Affected Systems

The affected product is Cyrus IMAPd, which supports the JMAP protocol. No specific version information is provided, so all deployments that use JMAP should be evaluated for this issue.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate severity, and the EPSS score is not available. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is an application‑level request to the JMAP snooze endpoint, requiring authentication to the IMAP server and the ability to craft a snooze request. The exploit conditions are that the attacker can authenticate as a user and target a mailbox for which they lack proper ACL privileges. No public exploit has been documented, but the moderate score suggests that the potential effect is meaningful in environments where mailbox privacy is critical.

Generated by OpenCVE AI on September 9, 2026 at 22:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to the latest release of Cyrus IMAPd that contains the ACL check fix. If a patch is not yet available, consider disabling the JMAP snooze functionality or restricting JMAP access to trusted users. Monitor JMAP activity logs for suspicious snooze requests targeting mailboxes for which the requesting user normally has no write permissions. Apply any vendor‑issued workarounds or configuration changes as soon as they become available.
  • Examine and, if possible, apply any vendor-provided configuration changes that enforce ACL checks on snooze operations.
  • Review mailbox ACLs regularly and ensure that users have only the necessary permissions; consider implementing stricter ACL policies for sensitive mailboxes.

Generated by OpenCVE AI on September 9, 2026 at 22:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 09 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE. An issue was discovered in Cyrus IMAP before 3.12.4. JMAP snooze bypasses the destination-mailbox ACL. An authenticated user with insert permissions on another user's snoozed mailbox could cause insertion of mail to that user's inbox, or any other of their mailboxes whose id was known to the user, despite having no insert permissions to the target mailbox.
First Time appeared Cyrusimap
Cyrusimap cyrus Imap
Weaknesses CWE-863
CPEs cpe:2.3:a:cyrusimap:cyrus_imap:*:*:*:*:*:*:*:*
Vendors & Products Cyrusimap
Cyrusimap cyrus Imap
References

Wed, 09 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 09 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE.
Title cyrus-imapd: cyrus-imapd: JMAP snooze bypasses destination-mailbox ACL
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

threat_severity

Moderate


Subscriptions

Cyrusimap Cyrus Imap
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-14T15:41:32.424Z

Reserved: 2026-07-13T00:00:00.000Z

Link: CVE-2026-61907

cve-icon Vulnrichment

Updated: 2026-09-14T15:39:56.860Z

cve-icon NVD

Status : Deferred

Published: 2026-09-09T19:17:28.927

Modified: 2026-09-14T16:17:17.010

Link: CVE-2026-61907

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-09T08:02:56Z

Links: CVE-2026-61907 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T02:45:17Z

Weaknesses