Impact
An authenticated user who has the maySetKeywords privilege on another user’s mailbox can change that mailbox’s special-use annotation via the mailbox/set command in Cyrus IMAP. This allows the sharee to alter the shared mailbox to have roles such as archived or snoozed, potentially causing emails to be directed to a mailbox that the sharee was not intended to receive. The vulnerability is a form of authorization bypass through user-controlled keys, where a privileged user can modify object metadata. The impact is that a user can gain undesired visibility or control over mail flows in shared mailboxes.
Affected Systems
The flaw exists in Cyrus IMAP versions prior to 3.12.4, as documented in the public release notes for 3.10.4, 3.12.4, and 3.8.8. Any deployment of Cyrus IMAP that remains on an affected version is susceptible. The vendor product is Cyrus IMAP, so environment administrators should verify the installed version and apply the fix once available.
Risk and Exploitability
The CVSS score is 3.5, indicating low overall risk, and the EPSS score is not available. The vulnerability is not listed in CISA’s KEV catalog. An attack requires authenticated access with maySetKeywords privilege, so an attacker needs to compromise or non‑repudiantly act as a legitimate user with that permission. No additional exploitation conditions are specified, and the vulnerability is unlikely to be widely leveraged outside of organizations that grant excessive mailbox permissions.
OpenCVE Enrichment