CVE-2026-61907
Deferred Deferred - Pending Action

JMAP Snooze ACL Bypass in Cyrus IMAP

Vulnerability report for CVE-2026-61907, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-14

Assigner: MITRE

Description

An issue was discovered in Cyrus IMAP before 3.12.4. JMAP snooze bypasses the destination-mailbox ACL. An authenticated user with insert permissions on another user's snoozed mailbox could cause insertion of mail to that user's inbox, or any other of their mailboxes whose id was known to the user, despite having no insert permissions to the target mailbox.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-14
Generated
2026-09-30
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
cyrus imap to 3.12.4 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Cyrus IMAP before 3.12.4 allows an authenticated user with insert permissions on a snoozed mailbox to bypass destination-mailbox ACLs. This means they can insert mail into another user's inbox or any other mailbox they know the ID of, even without insert permissions for the target mailbox.

Detection Guidance

This vulnerability involves JMAP snooze bypassing ACLs in Cyrus IMAP. To detect it, check Cyrus IMAP logs for unauthorized mail insertions into user mailboxes. Look for events where users with insert permissions on snoozed mailboxes attempt to insert mail into other users' mailboxes. Verify if the destination mailbox IDs were known to the user but lacked proper permissions.

Impact Analysis

If you use Cyrus IMAP, an attacker with valid credentials could exploit this to send unauthorized emails to your inbox or other mailboxes. This could lead to data leaks, spam, or phishing attempts using your account. The impact is limited to authenticated users with specific permissions.

Compliance Impact

This vulnerability could potentially violate compliance with GDPR and HIPAA by allowing unauthorized access to user mailboxes. The issue permits authenticated users to insert mail into another user's mailboxes despite lacking proper permissions, which may lead to unauthorized data exposure or manipulation. This could result in unauthorized access to sensitive personal or health information, violating data protection requirements.

Mitigation Strategies

Upgrade Cyrus IMAP to version 3.12.4 or later to address the JMAP snooze ACL bypass vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-61907. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart