SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-47087

LOW · CVSS 3.5 EPSS 0.19%

Source: NVD + CISA KEV + EPSS · Published 2026-07-16 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

Cyrus IMAP versions up to 3.12.2 are vulnerable due to a flaw in the URLAUTH mechanism, which fails to revoke access for previously authorized URLs even after the authorizer's permissions have been revoked. This could lead to unauthorized access to resources, potentially exposing sensitive data. Organizations using affected versions should prioritize remediation to mitigate the risk of unauthorized data exposure.

CVE
CVE-2026-47087
Severity
LOW
CVSS
3.5
EPSS
0.19%

Original NVD Description

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH does not honor revoked authorizer access. A URLAUTH URL minted while the authorizer had access continued to work after that access was revoked.