Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-61910

Quick assessment

Affected
cyrusimap Cyrus IMAP
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Cyrus IMAP 3.12.4 之前的版本中发现了一个问题:Mailbox/set 接口允许共享者(sharee)修改共享邮箱的特殊用途(special-use)角色。拥有对他人邮箱的 maySetKeywords 权限的已认证用户,可以修改该邮箱的特殊用途注解(specialuse annotation)。这使得共享者能够将共享邮箱的角色更改为已归档(archived)、已暂停(snoozed)或其他特定角色,从而导致邮件可能被写入该共享邮箱,进而使比预期更多的邮件内容被共享。(这种情况相对罕见,且如果目

CVSS 3.5 · Low

Possible ATT&CK Techniques 1 AI

T1531 · Account Access Removal
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-61910

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
An issue was discovered in Cyrus IMAP before 3.12.4. Mailbox/set let a sharee change a special-use role on shared mailboxes. An authenticated user with maySetKeywords on another user's mailbox could change that mailbox's specialuse annotation. This could allow the sharee to change the shared mailbox to perform the archived, snoozed, or other role, which might cause mail mail to be written to the shared mailbox, sharing more content than intended. (This is likely to be an unusual situation, made more unusual because if the target already has an non-shared mailbox with that role, role duplication suppression will prevent the update.)
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制不正确
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
cyrusimap Cyrus IMAP 0 ~ 3.8.8 -

II. Public POCs for CVE-2026-61910

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-61910

登录查看更多情报信息。

Vendor Pages for CVE-2026-61910 (4)

Same Patch Batch · cyrusimap · 2026-09-09 · 6 CVEs total

CVE-2026-61907 4.3 MEDIUM Cyrus IMAP 3.12.4前JMAP Snooze ACL绕过
CVE-2026-61911 4.3 MEDIUM Cyrus IMAP 3.12.4前Sieve邮箱存在性预言
CVE-2026-61915 4.2 MEDIUM Cyrus IMAP 3.12.4前 认证用户致CalDAV进程崩溃
CVE-2026-61909 3.5 LOW Cyrus IMAP 3.12.4前 CalDAV多获取ACL绕过
CVE-2026-61908 3.1 LOW Cyrus IMAP<3.12.4 JMAP越界读堆内存

IV. Related Vulnerabilities

V. Comments for CVE-2026-61910

No comments yet


Leave a comment