https://seclists.org/oss-sec/2026/q3/170: Cyrus IMAP 3.12.3 fixed 9 CVEs
Published Jul 17, 2026
·Updated
Affected Software
1 affected component
Cyrus IMAP Cyrus IMAP=3.12.3
The LOCALDELETE issue requires an authenticated non-admin user. The GENURLAUTH, URLAUTH, and XAPPLEPUSHSERVICE issues are described as exploitable by authenticated IMAP users; no administrative role is required for those cases.
No. An authenticated user could create a URLAUTH token for a mailbox without read access, and a URLAUTH URL created before the authorizer's access was revoked could continue to work afterward.
An authenticated IMAP user could use XAPPLEPUSHSERVICE to determine whether arbitrary mailboxes exist on other users' accounts. They could then create Apple Push Notification Service notifications for new mail in those mailboxes.