CVE-2026-47084: Medium severity Cyrus cyrus-imapd vulnerability
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. The LOCALDELETE command bypassed ACL checks. An authenticated but non-admin user could invoke the admin-only LOCALDELETE IMAP command and delete mailboxes for which they had no permissions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47084?
The severity of CVE-2026-47084 is medium with a CVSS score of 6.5.
What impact does CVE-2026-47084 have on security?
CVE-2026-47084 allows authenticated non-admin users to bypass ACL checks and delete mailboxes they do not have permissions for.
How do I fix CVE-2026-47084?
To fix CVE-2026-47084, update your Cyrus IMAP installation to the latest version that addresses this vulnerability.
Who is affected by CVE-2026-47084?
Authenticated users who are not administrators can be affected by CVE-2026-47084 if they have access to the LOCALDELETE command.
What command is involved in CVE-2026-47084?
The LOCALDELETE command is involved in CVE-2026-47084 and is exploited to delete mailboxes without proper permissions.