Known Vulnerabilities for Cyrus IMAP by Cyrusimap
Listed below are 1 of the newest known vulnerabilities associated with "Cyrus IMAP" by "Cyrusimap".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-61915 json | An issue was discovered in Cyrus IMAP before 3.12.4. There is a VPATCH BYPARAM double-free. An authenticated calendar user co... | Not Provided | 2026-09-09 | 2026-09-10 |
| CVE-2026-61911 json | An issue was discovered in Cyrus IMAP before 3.12.4. There is a Sieve mailbox existence oracle. An authenticated user could i... | Not Provided | 2026-09-09 | 2026-09-10 |
| CVE-2026-61910 json | An issue was discovered in Cyrus IMAP before 3.12.4. Mailbox/set let a sharee change a special-use role on shared mailboxes. ... | Not Provided | 2026-09-09 | 2026-09-14 |
| CVE-2026-61909 json | An issue was discovered in Cyrus IMAP before 3.12.4. CalDAV/CardDAV multiget bypasses a per-href ACL. An authenticated DAV us... | Not Provided | 2026-09-09 | 2026-09-14 |
| CVE-2026-61908 json | An issue was discovered in Cyrus IMAP before 3.12.4. A JMAP email-header blob ID can reference an out-of-bounds index. An aut... | Not Provided | 2026-09-09 | 2026-09-10 |
| CVE-2026-61907 json | An issue was discovered in Cyrus IMAP before 3.12.4. JMAP snooze bypasses the destination-mailbox ACL. An authenticated user ... | Not Provided | 2026-09-09 | 2026-09-14 |
| CVE-2026-47089 json | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. LISTRIGHTS os not limited to users with admin access. An... | Not Provided | 2026-07-16 | 2026-07-16 |
| CVE-2026-47088 json | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is heap exposure in nested MIME comment parsing. A... | Not Provided | 2026-07-16 | 2026-07-16 |
| CVE-2026-47087 json | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH does not honor revoked authorizer access. A URLA... | Not Provided | 2026-07-16 | 2026-07-16 |
| CVE-2026-47086 json | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. GENURLAUTH-issued tokens can bypass ACLs. Any authentica... | Not Provided | 2026-07-16 | 2026-07-16 |