
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-61907 is an incorrect authorization vulnerability in Cyrus IMAP affecting the JMAP snooze feature, where the destination-mailbox ACL is bypassed. An authenticated user with insert permissions on another user's snoozed mailbox can cause mail to be inserted into that user's inbox or any other mailbox whose ID is known, even without explicit insert permissions on the target mailbox. Affected versions include Cyrus IMAP before 3.8.8, 3.9.0–3.10.3, and 3.11.0–3.12.3. The vulnerability was published on September 9, 2026, with a CVSS v3.1 base score of 4.3 (Medium) (Red Hat Advisory, GitHub Advisory).
The root cause is classified as CWE-863 (Incorrect Authorization): when a JMAP snooze operation is processed, the server fails to verify that the authenticated user has insert permissions on the destination mailbox — it only checks permissions on the snoozed mailbox. This allows the attacker to specify an arbitrary target mailbox ID (inbox or any other mailbox) as the snooze destination, and the server will deliver mail there without enforcing the appropriate ACL on that target. Exploitation requires network access to the IMAP server, a valid authenticated session, and insert permissions on at least one of the victim's snoozed mailboxes, as well as knowledge of the target mailbox's ID (Red Hat Bugzilla, GitHub Advisory).
Successful exploitation allows an authenticated attacker to inject arbitrary mail into another user's mailboxes without authorization, violating the integrity of the victim's mailbox. There is no confidentiality or availability impact — the attacker cannot read or delete mail, only insert it. This could be used for phishing, social engineering, or disrupting mail workflows by planting messages in targeted mailboxes (GitHub Advisory, Red Hat Advisory).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported for this vulnerability. The EPSS score is 0.0, indicating very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation requires authentication and specific permissions (insert access to a victim's snoozed mailbox), which significantly limits the attacker pool (GitHub Advisory, Red Hat Advisory).
Mailbox/get) to discover the IDs of the victim user's mailboxes, including their inbox.Email/set or snooze-related API call that specifies the victim's target mailbox ID as the snooze destination, bypassing the ACL check on that mailbox.Email/set requests from a user targeting mailboxes belonging to a different user account; unexpected mail delivery events to mailboxes where the sender lacks explicit insert ACL.Upgrade Cyrus IMAP to one of the patched versions: 3.8.8, 3.10.4, or 3.12.4. Release notes for each fixed version are available on the Cyrus IMAP website. No configuration-based workaround has been published; upgrading to a patched release is the recommended remediation. Administrators should also review and minimize shared mailbox insert permissions as a defense-in-depth measure (Cyrus 3.12.4 Release Notes, Cyrus 3.10.4 Release Notes, Cyrus 3.8.8 Release Notes).
Fix availability across major Linux distributions and their releases.
bionic (esm-apps)
cyrus-imapd
devel
cyrus-imapd
focal (esm-apps)
cyrus-imapd
jammy
cyrus-imapd
jammy (esm-apps)
cyrus-imapd
noble
cyrus-imapd
noble (esm-apps)
cyrus-imapd
resolute
cyrus-imapd
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."