Description
An issue was discovered in Cyrus IMAP before 3.12.4. CalDAV/CardDAV multiget bypasses a per-href ACL. An authenticated DAV user with some shared access to another user's calendar or address book could read even unshared events or contacts by including the target hrefs in a calendar-multiget or addressbook-multiget REPORT.
Published: 2026-09-09
Score: 3.5 Low
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Disclosure
Action: Patch
AI Analysis

Impact

An authenticated CalDAV or CardDAV user who has been granted some shared access to another user's calendar or address book can craft a multiget REPORT request that includes the hrefs of calendar events or contacts that the target user has not shared. Because the server failed to enforce the per-href access control list for the multiget operation, the requester can retrieve the private data of the target user. This vulnerability allows unauthorized disclosure of calendar events and contact information and is classified as a trust boundary bypass (CWE‑420).

Affected Systems

The vulnerability exists in Cyrus IMAP deployments running any version released before 3.12.4. Relevant released versions affected include 3.10.4, 3.12.3, and earlier releases such as 3.8.8. Administrators should review the version numbers of their Cyrus IMAP installations and compare them against the official release notes that announce the fix in 3.12.4.

Risk and Exploitability

With a CVSS score of 3.5 the flaw is considered low impact. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating a low likelihood of widespread exploitation. However, the attack requires a legitimate DAV account that has been granted a minimal level of shared access to the victim's data, so the risk is confined to environments where such cross-user sharing is enabled. The fix requires updating to a patched version; no publicly available exploit is documented at this time.

Generated by OpenCVE AI on September 9, 2026 at 22:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Cyrus IMAP to version 3.12.4 or later, which contains the patch for the multiget ACL bypass.
  • After upgrading, verify that multiget REPORT requests are only allowed for users who have explicit per-href ACL permissions, or disable the multiget feature entirely if not required.
  • Review user sharing settings to ensure that only trusted users receive shared calendar or address book access, reducing the exposure of private hrefs to potential attackers.

Generated by OpenCVE AI on September 9, 2026 at 22:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Cyrus
Cyrus imap
CPEs cpe:2.3:a:cyrus:imap:*:*:*:*:*:*:*:*
Vendors & Products Cyrus
Cyrus imap

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Title CalDAV/CardDAV Multiget ACL Bypass in Cyrus IMAP cyrus-imapd: cyrus-imapd: CalDAV/CardDAV multiget bypasses per-href ACL
References
Metrics threat_severity

None

threat_severity

Moderate


Wed, 09 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Title CalDAV/CardDAV Multiget ACL Bypass in Cyrus IMAP

Wed, 09 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description An issue was discovered in Cyrus IMAP before 3.12.4. CalDAV/CardDAV multiget bypasses a per-href ACL. An authenticated DAV user with some shared access to another user's calendar or address book could read even unshared events or contacts by including the target hrefs in a calendar-multiget or addressbook-multiget REPORT.
First Time appeared Cyrusimap
Cyrusimap cyrus Imap
Weaknesses CWE-420
CPEs cpe:2.3:a:cyrusimap:cyrus_imap:*:*:*:*:*:*:*:*
Vendors & Products Cyrusimap
Cyrusimap cyrus Imap
References
Metrics cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-14T15:21:10.144Z

Reserved: 2026-07-13T00:00:00.000Z

Link: CVE-2026-61909

cve-icon Vulnrichment

Updated: 2026-09-14T15:21:06.557Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T20:18:36.523

Modified: 2026-09-16T15:24:24.070

Link: CVE-2026-61909

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-10T07:42:41Z

Links: CVE-2026-61909 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T13:30:12Z

Weaknesses
  • CWE-420

    Unprotected Alternate Channel