SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-61911

MEDIUM · CVSS 4.3 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-09-09 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

Cyrus IMAP versions prior to 3.12.4 are vulnerable to a Sieve mailbox existence oracle, allowing authenticated users to determine the existence of other users' private mailboxes or access shared mailbox annotations. This could lead to unauthorized information disclosure, potentially compromising user privacy. Organizations using affected versions of Cyrus IMAP should prioritize patching to mitigate this risk.

CVE
CVE-2026-61911
Severity
MEDIUM
CVSS
4.3
EPSS
0.22%
Oracle

Original NVD Description

An issue was discovered in Cyrus IMAP before 3.12.4. There is a Sieve mailbox existence oracle. An authenticated user could install a Sieve script that probed whether another user's private mailbox existed, or read the value of shared mailbox annotations, by observing which fileinto branch fired during LMTP delivery.