Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-61911

Quick assessment

Affected
cyrusimap Cyrus IMAP
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Cyrus IMAP 在 3.12.4 之前的版本中存在一个安全问题:存在一个“Sieve 邮箱存在性预言机”(Sieve mailbox existence oracle)。一个经过认证的用户可以安装一个 Sieve 脚本,通过观察 LMTP 投递过程中哪个 分支被触发,来探测其他用户的私有邮箱是否存在,或者读取共享邮箱的注释(annotations)值。

CVSS 4.3 · Medium

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-61911

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
An issue was discovered in Cyrus IMAP before 3.12.4. There is a Sieve mailbox existence oracle. An authenticated user could install a Sieve script that probed whether another user's private mailbox existed, or read the value of shared mailbox annotations, by observing which fileinto branch fired during LMTP delivery.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
将系统数据暴露到未授权控制的范围
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
cyrusimap Cyrus IMAP 0 ~ 3.8.8 -

II. Public POCs for CVE-2026-61911

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-61911

登录查看更多情报信息。

Vendor Pages for CVE-2026-61911 (4)

Same Patch Batch · cyrusimap · 2026-09-09 · 6 CVEs total

CVE-2026-61907 4.3 MEDIUM Cyrus IMAP 3.12.4前JMAP Snooze ACL绕过
CVE-2026-61915 4.2 MEDIUM Cyrus IMAP 3.12.4前 认证用户致CalDAV进程崩溃
CVE-2026-61910 3.5 LOW Cyrus IMAP 3.12.4前共享邮箱权限控制缺陷
CVE-2026-61909 3.5 LOW Cyrus IMAP 3.12.4前 CalDAV多获取ACL绕过
CVE-2026-61908 3.1 LOW Cyrus IMAP<3.12.4 JMAP越界读堆内存

IV. Related Vulnerabilities

V. Comments for CVE-2026-61911

No comments yet


Leave a comment