SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-47084

MEDIUM · CVSS 6.5 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-07-16 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

Cyrus IMAP versions up to 3.12.2 are vulnerable due to a flaw in the LOCALDELETE command, which allows authenticated non-admin users to bypass access control list (ACL) checks and delete mailboxes without proper permissions. This could lead to unauthorized data loss and disruption of services. Organizations using affected versions should prioritize remediation to prevent potential misuse of this vulnerability.

CVE
CVE-2026-47084
Severity
MEDIUM
CVSS
6.5
EPSS
0.21%

Original NVD Description

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. The LOCALDELETE command bypassed ACL checks. An authenticated but non-admin user could invoke the admin-only LOCALDELETE IMAP command and delete mailboxes for which they had no permissions.