These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-47089 is a vulnerability in Cyrus IMAP through 3.12.2 where LISTRIGHTS is not limited to users with admin access. An authenticated user could call IMAP LISTRIGHTS against any mailbox they could name and learn what principals had what access to it. This action should have been restricted to users with admin access on the target mailbox. The vulnerability exists due to inadequate access controls in [truncated]
CVE-2026-47088 is a low-severity vulnerability in Cyrus IMAP through 3.12.2, caused by improper parsing of nested MIME comments. An authenticated IMAP user could craft an email message containing an RFC 822 comment ending with a backslash, leading to heap exposure. This vulnerability has a CVSS score of 3.1 and is classified as LOW severity. The CVE record was published on 2026-07-16T19:16:49.513Z and has [truncated]
A low-severity vulnerability was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. The issue involves URLAUTH not honoring revoked authorizer access, allowing a URLAUTH URL minted while the authorizer had access to continue working after that access was revoked. This vulnerability could potentially allow unauthorized access to sensitive information if exploited. System administrators and security te [truncated]
CVE-2026-47086 is a vulnerability in cyrus-imapd, part of Cyrus IMAP, that allows authenticated users to bypass Access Control Lists (ACLs). The issue arises from the GENURLAUTH command, which can be used to mint URLAUTH tokens for any mailbox a user can name, even if they lack read access to it. This could enable users to read mail from mailboxes they shouldn't have access to, potentially leading to unau [truncated]
A MEDIUM severity vulnerability was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. The issue allows for URLAUTH token forgery via a missing mboxkey. An attacker who knows a folder name on the victim's account for which the victim has never issued an auth URL can forge a working URLAUTH token by computing an HMAC-SHA1 value with a predictable key, granting them read access to the mailbox. However, [truncated]
An authenticated but non-admin user could invoke the admin-only LOCALDELETE IMAP command and delete mailboxes for which they had no permissions due to a LOCALDELETE ACL check bypass in Cyrus IMAP through 3.12.2. This issue allows unauthorized mailbox deletion, potentially leading to data loss. The vulnerability has a CVSS score of 6.5, indicating a medium severity level. Users of Cyrus IMAP through versio [truncated]
CVE-2026-47083 is a MEDIUM severity vulnerability in Cyrus IMAP through 3.12.2. An issue was discovered in cyrus-imapd, allowing an authenticated IMAP user to enumerate folder names under any account they could name using the ESEARCH command. This vulnerability has a significant impact on the security of the IMAP service, as it allows for the enumeration of folder names under any account. Users of Cyrus I [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-16T19:16:48.713Z and has not been modified since then. This issue affects Cyrus IMAP through 3.12.2, specifically the vacation 'fcc' feature which skips the destination-mailbox ACL. The vulnerability allows users to deliver vacation auto-reply copies into any mailbox they can name, regardless of the [truncated]
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an XAPPLEPUSHSERVICE folder existence oracle and push hijack. An authenticated IMAP user could probe for the existence of arbitrary mailboxes on other users' accounts via the XAPPLEPUSHSERVICE command and then create Apple Push Notification Service notifications for new mail in those mailboxes to their own APNS device. This issu [truncated]