Impact
The vulnerability in Cyrus IMAP before version 3.12.4 allows an authenticated user with insert permissions on another user's snoozed mailbox to bypass destination‑mailbox ACL checks. By issuing a JMAP snooze command, the user can cause mail to be inserted into the target user's inbox or any other mailbox whose ID is known, even though that user has no insert permissions on the destination mailbox. This represents a serious authorization bypass, enabling an attacker to read, move, or tamper with messages in mailboxes they should not access.
Affected Systems
The affected product is Cyrus IMAPd, which supports the JMAP protocol. No specific version information is provided, so all deployments that use JMAP should be evaluated for this issue.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, and the EPSS score is not available. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is an application‑level request to the JMAP snooze endpoint, requiring authentication to the IMAP server and the ability to craft a snooze request. The exploit conditions are that the attacker can authenticate as a user and target a mailbox for which they lack proper ACL privileges. No public exploit has been documented, but the moderate score suggests that the potential effect is meaningful in environments where mailbox privacy is critical.
OpenCVE Enrichment