CVE-2026-61909
Undergoing Analysis Undergoing Analysis - In Progress

CalDAV/CardDAV Multiget ACL Bypass in Cyrus IMAP

Vulnerability report for CVE-2026-61909, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-14

Assigner: MITRE

Description

An issue was discovered in Cyrus IMAP before 3.12.4. CalDAV/CardDAV multiget bypasses a per-href ACL. An authenticated DAV user with some shared access to another user's calendar or address book could read even unshared events or contacts by including the target hrefs in a calendar-multiget or addressbook-multiget REPORT.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-14
Generated
2026-09-30
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-29
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
cyrus imap to 3.12.4 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-420 The product protects a primary channel, but it does not use the same level of protection for an alternate channel.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in Cyrus IMAP before version 3.12.4. It involves a flaw in the CalDAV/CardDAV multiget feature where an authenticated user with limited shared access to another user's calendar or address book can bypass per-href access controls. By including specific target hrefs in a calendar-multiget or addressbook-multiget REPORT request, the user can read events or contacts that are otherwise unshared.

Detection Guidance

This vulnerability affects Cyrus IMAP versions before 3.12.4 and involves improper ACL enforcement during CalDAV/CardDAV multiget operations. Detection requires checking the Cyrus IMAP server version and reviewing DAV access logs for unauthorized data access attempts. No specific commands are provided in the context to directly detect this issue.

Impact Analysis

If you use Cyrus IMAP with CalDAV/CardDAV services, an attacker with authenticated access could exploit this to read your private calendar events or address book contacts even if they were not explicitly shared with them. This could lead to unauthorized access to sensitive personal or organizational data.

Compliance Impact

This vulnerability could violate data protection regulations like GDPR or HIPAA by allowing unauthorized access to personal or health-related data. Organizations using affected versions of Cyrus IMAP may face compliance risks due to potential data breaches and insufficient access controls.

Mitigation Strategies

Upgrade Cyrus IMAP to version 3.12.4 or later to address the ACL bypass issue in CalDAV/CardDAV multiget requests.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-61909. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart