An issue was discovered in Cyrus IMAP before 3.12.4. JMAP snooze bypasses the destination-mailbox ACL. An authenticated user with insert permissions on another user's snoozed mailbox could cause insertion of mail to that user's inbox, or any other of their mailboxes whose id was known to the user, despite having no insert permissions to the target mailbox.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 09 Sep 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 |
Wed, 09 Sep 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | No description is available for this CVE. | An issue was discovered in Cyrus IMAP before 3.12.4. JMAP snooze bypasses the destination-mailbox ACL. An authenticated user with insert permissions on another user's snoozed mailbox could cause insertion of mail to that user's inbox, or any other of their mailboxes whose id was known to the user, despite having no insert permissions to the target mailbox. |
| First Time appeared |
Cyrusimap
Cyrusimap cyrus Imap |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:cyrusimap:cyrus_imap:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Cyrusimap
Cyrusimap cyrus Imap |
|
| References |
|
Wed, 09 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 |
Wed, 09 Sep 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | No description is available for this CVE. | |
| Title | cyrus-imapd: cyrus-imapd: JMAP snooze bypasses destination-mailbox ACL | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-09-09T19:02:00.754Z
Reserved: 2026-07-13T00:00:00.000Z
Link: CVE-2026-61907
No data.
Status : Deferred
Published: 2026-09-09T19:17:28.927
Modified: 2026-09-09T20:11:44.187
Link: CVE-2026-61907
OpenCVE Enrichment
Updated: 2026-09-09T21:30:15Z
Weaknesses