SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-47082

MEDIUM · CVSS 5.4 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-07-16 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The vacation "fcc" feature in Cyrus IMAP versions up to 3.12.2 allows users to bypass destination-mailbox access control lists (ACLs), enabling them to deliver auto-reply copies to any specified mailbox, even if they lack insert permissions. This vulnerability could lead to unauthorized access to mailbox contents, potentially exposing sensitive information. Organizations using affected versions of Cyrus IMAP should prioritize remediation to mitigate the risk of data leakage.

CVE
CVE-2026-47082
Severity
MEDIUM
CVSS
5.4
EPSS
0.20%

Original NVD Description

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. The vacation "fcc" feature skips the destination-mailbox ACL. A user whose vacation Sieve script used :fcc (to save a copy of the sent message) could deliver vacation auto-reply copies into any mailbox the script could name, regardless of whether the script owner had insert permissions on the destination mailbox.