PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-61910 cyrusimap CVE debrief

An issue in Cyrus IMAP before 3.12.4 allows an authenticated user with maySetKeywords on another user's mailbox to change that mailbox's special-use annotation, potentially causing unintended content sharing. This could allow the sharee to change the shared mailbox to perform the archived, snoozed, or other role, which might cause mail to be written to the shared mailbox, sharing more content than intended. The vulnerability is likely to be an unusual situation, made more unusual because if the target already has a non-shared mailbox with that role, role duplication suppression will prevent the update.

Vendor
cyrusimap
Product
Cyrus IMAP
CVSS
LOW 3.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-09
Original CVE updated
2026-09-14
Advisory published
2026-09-09
Advisory updated
2026-09-14

Who should care

Defenders responsible for Cyrus IMAP server administration and user management should assess exposure and verify mailbox configurations. They should prioritize verifying Cyrus IMAP mailbox configurations and user permissions to prevent unauthorized mailbox role changes, which could lead to unintended content sharing. Additionally, defenders should review compensating controls for exposed systems while remediation is scheduled and verified.

Why it matters

Defenders should prioritize verifying Cyrus IMAP mailbox configurations and user permissions to prevent unauthorized mailbox role changes, which could lead to unintended content sharing.

  • Potential unintended content sharing due to mailbox role changes
  • Need to verify Cyrus IMAP mailbox configurations and user permissions
  • Possible impact on mail routing and storage

Technical summary

An authenticated user with maySetKeywords on another user's mailbox could change that mailbox's special-use annotation, potentially causing unintended content sharing. This vulnerability exists in Cyrus IMAP before 3.12.4. The user could change the mailbox's special-use role, which might cause mail to be written to the shared mailbox, sharing more content than intended. Defenders should prioritize verifying Cyrus IMAP mailbox configurations and user permissions to prevent unauthorized mailbox role changes, which could lead to unintended content sharing.

Defensive priority

Defenders should prioritize verifying Cyrus IMAP mailbox configurations and user permissions to prevent unauthorized mailbox role changes.

Recommended defensive actions

  • Verify Cyrus IMAP mailbox configurations and user permissions
  • Restrict maySetKeywords permissions to prevent unauthorized mailbox role changes
  • Monitor mailbox role changes for suspicious activity
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide details on the mailbox role change vulnerability in Cyrus IMAP before 3.12.4. The vulnerability allows an authenticated user with maySetKeywords on another user's mailbox to change that mailbox's special-use annotation. This could lead to unintended content sharing. Defenders should verify mailbox configurations and user permissions to prevent unauthorized mailbox role changes.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-61910 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-61910

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-61910 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-61910

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.