https://seclists.org/oss-sec/2026/q3/170: Cyrus IMAP 3.12.3 fixed 9 CVEs
Published Jul 17, 2026
·Updated
Affected Software
1 affected component
Cyrus IMAP Cyrus IMAP=3.12.3
Frequently Asked Questions
1
Who can exploit the documented access-control issues?
The LOCALDELETE issue requires an authenticated non-admin user. The GENURLAUTH, URLAUTH, and XAPPLEPUSHSERVICE issues are described as exploitable by authenticated IMAP users; no administrative role is required for those cases.
2
Are mailbox ACLs sufficient to prevent unauthorized URL-based mail access?
No. An authenticated user could create a URLAUTH token for a mailbox without read access, and a URLAUTH URL created before the authorizer's access was revoked could continue to work afterward.
3
What is the operational impact of the XAPPLEPUSHSERVICE issue?
An authenticated IMAP user could use XAPPLEPUSHSERVICE to determine whether arbitrary mailboxes exist on other users' accounts. They could then create Apple Push Notification Service notifications for new mail in those mailboxes.