SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-47086

LOW · CVSS 3.5 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-07-16 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

Cyrus IMAP versions up to 3.12.2 are vulnerable due to a flaw in the GENURLAUTH command that allows authenticated users to generate URLAUTH tokens for any mailbox, bypassing access control lists (ACLs). This vulnerability enables unauthorized access to mailbox contents, potentially exposing sensitive information. Organizations using affected versions of Cyrus IMAP should prioritize remediation to prevent unauthorized data access.

CVE
CVE-2026-47086
Severity
LOW
CVSS
3.5
EPSS
0.18%

Original NVD Description

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. GENURLAUTH-issued tokens can bypass ACLs. Any authenticated user could mint a URLAUTH token (via the GENURLAUTH command) for any mailbox they could name, even without read access on it. This would allow reading mail from mailboxes despite having no granted permissions.