Description
An issue was discovered in Cyrus IMAP before 3.12.4. Mailbox/set let a sharee change a special-use role on shared mailboxes. An authenticated user with maySetKeywords on another user's mailbox could change that mailbox's specialuse annotation. This could allow the sharee to change the shared mailbox to perform the archived, snoozed, or other role, which might cause mail mail to be written to the shared mailbox, sharing more content than intended. (This is likely to be an unusual situation, made more unusual because if the target already has an non-shared mailbox with that role, role duplication suppression will prevent the update.)
Published: 2026-09-09
Score: 3.5 Low
EPSS: < 1% Very Low
KEV: No
Impact: Authorization Bypass
Action: Patch
AI Analysis

Impact

An authenticated user who has the maySetKeywords privilege on another user’s mailbox can change that mailbox’s special-use annotation via the mailbox/set command in Cyrus IMAP. This allows the sharee to alter the shared mailbox to have roles such as archived or snoozed, potentially causing emails to be directed to a mailbox that the sharee was not intended to receive. The vulnerability is a form of authorization bypass through user-controlled keys, where a privileged user can modify object metadata. The impact is that a user can gain undesired visibility or control over mail flows in shared mailboxes.

Affected Systems

The flaw exists in Cyrus IMAP versions prior to 3.12.4, as documented in the public release notes for 3.10.4, 3.12.4, and 3.8.8. Any deployment of Cyrus IMAP that remains on an affected version is susceptible. The vendor product is Cyrus IMAP, so environment administrators should verify the installed version and apply the fix once available.

Risk and Exploitability

The CVSS score is 3.5, indicating low overall risk, and the EPSS score is not available. The vulnerability is not listed in CISA’s KEV catalog. An attack requires authenticated access with maySetKeywords privilege, so an attacker needs to compromise or non‑repudiantly act as a legitimate user with that permission. No additional exploitation conditions are specified, and the vulnerability is unlikely to be widely leveraged outside of organizations that grant excessive mailbox permissions.

Generated by OpenCVE AI on September 9, 2026 at 22:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Cyrus IMAP to version 3.12.4 or later, which removes the ability to change special-use roles via mailbox/set for sharees
  • Restrict the maySetKeywords capability to only users who require it, reducing the attack surface for shared mailbox manipulation
  • Review shared mailbox configurations and audit any special-use annotations to ensure they reflect the correct visibility and roles

Generated by OpenCVE AI on September 9, 2026 at 22:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Cyrus
Cyrus imap
CPEs cpe:2.3:a:cyrus:imap:*:*:*:*:*:*:*:*
Vendors & Products Cyrus
Cyrus imap

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Title Shared Mailbox Special-Use Role Modification via mailbox/set cyrus-imapd: cyrus-imapd: Mailbox/set let sharee change special-use role on shared mailboxes
References
Metrics threat_severity

None

threat_severity

Moderate


Wed, 09 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
Title Shared Mailbox Special-Use Role Modification via mailbox/set

Wed, 09 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description An issue was discovered in Cyrus IMAP before 3.12.4. Mailbox/set let a sharee change a special-use role on shared mailboxes. An authenticated user with maySetKeywords on another user's mailbox could change that mailbox's specialuse annotation. This could allow the sharee to change the shared mailbox to perform the archived, snoozed, or other role, which might cause mail mail to be written to the shared mailbox, sharing more content than intended. (This is likely to be an unusual situation, made more unusual because if the target already has an non-shared mailbox with that role, role duplication suppression will prevent the update.)
First Time appeared Cyrusimap
Cyrusimap cyrus Imap
Weaknesses CWE-863
CPEs cpe:2.3:a:cyrusimap:cyrus_imap:*:*:*:*:*:*:*:*
Vendors & Products Cyrusimap
Cyrusimap cyrus Imap
References
Metrics cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-14T15:41:32.279Z

Reserved: 2026-07-13T00:00:00.000Z

Link: CVE-2026-61910

cve-icon Vulnrichment

Updated: 2026-09-14T15:39:54.889Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T20:18:36.663

Modified: 2026-09-16T15:24:04.610

Link: CVE-2026-61910

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-10T07:43:36Z

Links: CVE-2026-61910 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T01:15:14Z

Weaknesses