PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-61907 cyrusimap CVE debrief

An authenticated user with insert permissions on another user's snoozed mailbox could cause insertion of mail to that user's inbox, or any other of their mailboxes whose id was known to the user, despite having no insert permissions to the target mailbox. This issue arises from the JMAP snooze feature in Cyrus IMAP before 3.12.4, which bypasses the destination-mailbox ACL. The vulnerability allows for potential unauthorized mail insertion, emphasizing the need for verifying mailbox permissions and access controls.

Vendor
cyrusimap
Product
Cyrus IMAP
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-09
Original CVE updated
2026-09-14
Advisory published
2026-09-09
Advisory updated
2026-09-14

Who should care

IMAP administrators and users, particularly those with insert permissions on snoozed mailboxes, should verify mailbox permissions and access controls to prevent unauthorized mail insertion. This includes reviewing current permissions, restricting insert permissions for authenticated users, and monitoring mailbox activity for suspicious insertions. The issue's impact on security teams and vulnerability management processes underscores the need for prompt关注.

Why it matters

IMAP administrators and users should verify mailbox permissions and access controls to prevent unauthorized mail insertion.

  • Authenticated users with insert permissions on another user's snoozed mailbox can cause insertion of mail to that user's inbox or other mailboxes
  • Potential for unauthorized mail insertion

Technical summary

The issue is caused by the JMAP snooze feature in Cyrus IMAP before 3.12.4, which bypasses the destination-mailbox ACL. This allows an authenticated user with insert permissions on another user's snoozed mailbox to cause insertion of mail to that user's inbox or other mailboxes, despite lacking insert permissions for the target mailbox. The vulnerability highlights the importance of verifying mailbox permissions and access controls to prevent unauthorized mail insertion. Technical details indicate a medium severity, with a CVSS score of 4.3.

Defensive priority

IMAP administrators and users should verify mailbox permissions and access controls.

Recommended defensive actions

  • Verify mailbox permissions and access controls
  • Restrict insert permissions for authenticated users
  • Monitor mailbox activity for suspicious insertions
  • Review compensating controls for exposed systems
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The CVE record and NVD entry provide details on the issue. Evidence is limited to public CVE and NVD information. Defensive verification tasks include reviewing mailbox permissions, monitoring for suspicious insertions, and ensuring that insert permissions are properly restricted. The issue's scope and severity indicate a need for immediate attention from IMAP administrators and users.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-61907 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-61907

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-61907 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-61907

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.