Description
An issue was discovered in Cyrus IMAP before 3.12.4. There is a Sieve mailbox existence oracle. An authenticated user could install a Sieve script that probed whether another user's private mailbox existed, or read the value of shared mailbox annotations, by observing which fileinto branch fired during LMTP delivery.
Published: 2026-09-09
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information disclosure via mailbox existence oracle
Action: Immediate Patch
AI Analysis

Impact

An authenticated user can create a Sieve script that probes whether another user's private mailbox exists or reads shared mailbox annotations by observing which fileinto branch fires during LMTP delivery. This action reveals the existence of private mailboxes and potentially sensitive annotations, constituting an information‑disclosure flaw classified as CWE-497.

Affected Systems

Cyrus IMAP versions prior to 3.12.4, including releases 3.10.x and 3.8.x, are affected. The vulnerability is present regardless of deployment scale and applies to all users that can install Sieve scripts on the server.

Risk and Exploitability

The CVSS score of 4.3 indicates low‑to‑moderate severity and no EPSS score is reported, so the exploitation probability remains unknown. The flaw is not listed in the CISA KEV catalog. An attacker only needs valid user credentials to trigger the script. Based on the description, it is inferred that an attacker could obtain such credentials through phishing or credential theft. This would enable enumeration of private mailboxes and read‑only access to shared annotations, which can aid further intrusion or privacy violations.

Generated by OpenCVE AI on September 9, 2026 at 23:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Cyrus IMAP to version 3.12.4 or later to patch the flaw.
  • If Sieve scripting is not required for your operation, disable or restrict Sieve script installation for all users in the Cyrus IMAP configuration.
  • Employ strong authentication methods (multi‑factor authentication) and consider network segmentation to limit exposed IMAP server to trusted hosts.

Generated by OpenCVE AI on September 9, 2026 at 23:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Cyrus
Cyrus imap
CPEs cpe:2.3:a:cyrus:imap:*:*:*:*:*:*:*:*
Vendors & Products Cyrus
Cyrus imap

Thu, 10 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Title Sieve Mailbox Existence Oracle in Cyrus IMAP cyrus-imapd: cyrus-imapd: Sieve fileinto mailbox existence oracle
References
Metrics threat_severity

None

threat_severity

Moderate


Thu, 10 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
Title Sieve Mailbox Existence Oracle in Cyrus IMAP

Wed, 09 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Cyrusimap
Cyrusimap cyrus Imap
Weaknesses CWE-497
CPEs cpe:2.3:a:cyrusimap:cyrus_imap:*:*:*:*:*:*:*:*
Vendors & Products Cyrusimap
Cyrusimap cyrus Imap
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Wed, 09 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description An issue was discovered in Cyrus IMAP before 3.12.4. There is a Sieve mailbox existence oracle. An authenticated user could install a Sieve script that probed whether another user's private mailbox existed, or read the value of shared mailbox annotations, by observing which fileinto branch fired during LMTP delivery.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-10T19:01:53.316Z

Reserved: 2026-07-13T00:00:00.000Z

Link: CVE-2026-61911

cve-icon Vulnrichment

Updated: 2026-09-10T19:00:14.043Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T20:18:36.800

Modified: 2026-09-16T15:23:58.500

Link: CVE-2026-61911

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-10T07:43:45Z

Links: CVE-2026-61911 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T11:00:09Z

Weaknesses
  • CWE-497

    Exposure of Sensitive System Information to an Unauthorized Control Sphere