Impact
An authenticated CalDAV or CardDAV user who has been granted some shared access to another user's calendar or address book can craft a multiget REPORT request that includes the hrefs of calendar events or contacts that the target user has not shared. Because the server failed to enforce the per-href access control list for the multiget operation, the requester can retrieve the private data of the target user. This vulnerability allows unauthorized disclosure of calendar events and contact information and is classified as a trust boundary bypass (CWE‑420).
Affected Systems
The vulnerability exists in Cyrus IMAP deployments running any version released before 3.12.4. Relevant released versions affected include 3.10.4, 3.12.3, and earlier releases such as 3.8.8. Administrators should review the version numbers of their Cyrus IMAP installations and compare them against the official release notes that announce the fix in 3.12.4.
Risk and Exploitability
With a CVSS score of 3.5 the flaw is considered low impact. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating a low likelihood of widespread exploitation. However, the attack requires a legitimate DAV account that has been granted a minimal level of shared access to the victim's data, so the risk is confined to environments where such cross-user sharing is enabled. The fix requires updating to a patched version; no publicly available exploit is documented at this time.
OpenCVE Enrichment