Impact
An authenticated user can create a Sieve script that probes whether another user's private mailbox exists or reads shared mailbox annotations by observing which fileinto branch fires during LMTP delivery. This action reveals the existence of private mailboxes and potentially sensitive annotations, constituting an information‑disclosure flaw classified as CWE-497.
Affected Systems
Cyrus IMAP versions prior to 3.12.4, including releases 3.10.x and 3.8.x, are affected. The vulnerability is present regardless of deployment scale and applies to all users that can install Sieve scripts on the server.
Risk and Exploitability
The CVSS score of 4.3 indicates low‑to‑moderate severity and no EPSS score is reported, so the exploitation probability remains unknown. The flaw is not listed in the CISA KEV catalog. An attacker only needs valid user credentials to trigger the script. Based on the description, it is inferred that an attacker could obtain such credentials through phishing or credential theft. This would enable enumeration of private mailboxes and read‑only access to shared annotations, which can aid further intrusion or privacy violations.
OpenCVE Enrichment