在 Cyrus IMAP 3.12.4 之前的版本中,发现了一个安全问题:JMAP 的“snooze”(延迟/挂起)功能会绕过目标邮箱的访问控制列表(ACL)检查。具体而言,一个经过身份验证的用户,即使没有目标邮箱的插入权限,只要拥有另一个用户处于“snooze”状态邮箱的插入权限,就可以将邮件插入该用户的收件箱(inbox),或者插入该用户其他已知 ID 的邮箱,从而绕过正常的权限控制。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| cyrusimap | Cyrus IMAP | < 3.8.8 |
affected |
3.9.0< 3.10.4 |
affected | ||
3.11.0< 3.12.4 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| cyrusimap | Cyrus IMAP | 0 ~ 3.8.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-61911 | 4.3 MEDIUM | Cyrus IMAP 3.12.4前Sieve邮箱存在性预言 |
| CVE-2026-61915 | 4.2 MEDIUM | Cyrus IMAP 3.12.4前 认证用户致CalDAV进程崩溃 |
| CVE-2026-61910 | 3.5 LOW | Cyrus IMAP 3.12.4前共享邮箱权限控制缺陷 |
| CVE-2026-61909 | 3.5 LOW | Cyrus IMAP 3.12.4前 CalDAV多获取ACL绕过 |
| CVE-2026-61908 | 3.1 LOW | Cyrus IMAP<3.12.4 JMAP越界读堆内存 |
No comments yet