CVE-2026-47083: Medium severity Cyrus Cyrus IMAP vulnerability
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an ESEARCH cross-user content oracle. By using the ESEARCH command, an authenticated IMAP user could enumerate folder names under any account they could name. Search would return UIDs of messages matching the search, creating a content oracle (without allowing arbitrary reads of the target's content).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47083?
The severity of CVE-2026-47083 is rated as medium with a score of 4.3.
How do I fix CVE-2026-47083?
To mitigate CVE-2026-47083, it is recommended to upgrade to a patched version of Cyrus IMAP that addresses this vulnerability.
What kind of vulnerability is CVE-2026-47083?
CVE-2026-47083 is an ESEARCH cross-user content oracle vulnerability affecting Cyrus IMAP.
What impact does CVE-2026-47083 have?
CVE-2026-47083 allows an authenticated IMAP user to enumerate folder names under any account they specify.
Which versions of Cyrus IMAP are affected by CVE-2026-47083?
CVE-2026-47083 affects Cyrus IMAP up to version 3.12.2.