CyberRota Analysis
AI-GeneratedCyrus IMAP versions up to 3.12.2 are vulnerable due to a flaw in the URLAUTH mechanism, which fails to revoke access for previously authorized URLs even after the authorizer's permissions have been revoked. This could lead to unauthorized access to resources, potentially exposing sensitive data. Organizations using affected versions should prioritize remediation to mitigate the risk of unauthorized data exposure.
CVE
CVE-2026-47087
Severity
LOW
CVSS
3.5
EPSS
0.19%
Original NVD Description
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH does not honor revoked authorizer access. A URLAUTH URL minted while the authorizer had access continued to work after that access was revoked.