CVE-2026-47089: Medium severity Cyrus cyrus-imapd vulnerability
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. LISTRIGHTS os not limited to users with admin access. An authenticated user could call IMAP LISTRIGHTS against any mailbox they could name and learn what principals had what access to it. (This action should have been restricted to users with admin access on the target mailbox.)
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
cyrus-imapdto a version that resolves this vulnerability.Fixed in 3.12.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47089?
The severity of CVE-2026-47089 is rated as medium with a score of 4.3.
What does CVE-2026-47089 affect?
CVE-2026-47089 affects cyrus-imapd in Cyrus IMAP versions up to 3.12.2.
How do I fix CVE-2026-47089?
To fix CVE-2026-47089, update to the latest version of Cyrus IMAP that addresses this vulnerability.
Who can exploit CVE-2026-47089?
An authenticated user can exploit CVE-2026-47089 to access LISTRIGHTS information for mailboxes they name.
What kind of access does CVE-2026-47089 allow?
CVE-2026-47089 allows authenticated users to learn which principals have access rights to specific mailboxes.