PatchSiren cyber security CVE debrief
CVE-2026-61907 cyrusimap CVE debrief
An authenticated user with insert permissions on another user's snoozed mailbox could cause insertion of mail to that user's inbox, or any other of their mailboxes whose id was known to the user, despite having no insert permissions to the target mailbox. This issue arises from the JMAP snooze feature in Cyrus IMAP before 3.12.4, which bypasses the destination-mailbox ACL. The vulnerability allows for potential unauthorized mail insertion, emphasizing the need for verifying mailbox permissions and access controls.
- Vendor
- cyrusimap
- Product
- Cyrus IMAP
- CVSS
- MEDIUM 4.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-09
- Original CVE updated
- 2026-09-14
- Advisory published
- 2026-09-09
- Advisory updated
- 2026-09-14
Who should care
IMAP administrators and users, particularly those with insert permissions on snoozed mailboxes, should verify mailbox permissions and access controls to prevent unauthorized mail insertion. This includes reviewing current permissions, restricting insert permissions for authenticated users, and monitoring mailbox activity for suspicious insertions. The issue's impact on security teams and vulnerability management processes underscores the need for prompt关注.
Why it matters
IMAP administrators and users should verify mailbox permissions and access controls to prevent unauthorized mail insertion.
- Authenticated users with insert permissions on another user's snoozed mailbox can cause insertion of mail to that user's inbox or other mailboxes
- Potential for unauthorized mail insertion
Technical summary
The issue is caused by the JMAP snooze feature in Cyrus IMAP before 3.12.4, which bypasses the destination-mailbox ACL. This allows an authenticated user with insert permissions on another user's snoozed mailbox to cause insertion of mail to that user's inbox or other mailboxes, despite lacking insert permissions for the target mailbox. The vulnerability highlights the importance of verifying mailbox permissions and access controls to prevent unauthorized mail insertion. Technical details indicate a medium severity, with a CVSS score of 4.3.
Defensive priority
IMAP administrators and users should verify mailbox permissions and access controls.
Recommended defensive actions
- Verify mailbox permissions and access controls
- Restrict insert permissions for authenticated users
- Monitor mailbox activity for suspicious insertions
- Review compensating controls for exposed systems
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The CVE record and NVD entry provide details on the issue. Evidence is limited to public CVE and NVD information. Defensive verification tasks include reviewing mailbox permissions, monitoring for suspicious insertions, and ensuring that insert permissions are properly restricted. The issue's scope and severity indicate a need for immediate attention from IMAP administrators and users.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-61907 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-61907
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-61907 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-61907
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://cyrusimap.org/
-
Source reference
Unverified legacy reference
URL: https://www.cyrusimap.org/3.12/imap/download/release-notes/3.10/x/3.10.4.html
-
Source reference
Unverified legacy reference
URL: https://www.cyrusimap.org/3.12/imap/download/release-notes/3.12/x/3.12.4.html
-
Source reference
Unverified legacy reference
URL: https://www.cyrusimap.org/3.12/imap/download/release-notes/3.8/x/3.8.8.html
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.