CVE-2026-61907
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2026-61907 is an incorrect authorization vulnerability in Cyrus IMAP affecting the JMAP snooze feature, where the destination-mailbox ACL is bypassed. An authenticated user with insert permissions on another user's snoozed mailbox can cause mail to be inserted into that user's inbox or any other mailbox whose ID is known, even without explicit insert permissions on the target mailbox. Affected versions include Cyrus IMAP before 3.8.8, 3.9.0–3.10.3, and 3.11.0–3.12.3. The vulnerability was published on September 9, 2026, with a CVSS v3.1 base score of 4.3 (Medium) (Red Hat Advisory, GitHub Advisory).

Technical details

The root cause is classified as CWE-863 (Incorrect Authorization): when a JMAP snooze operation is processed, the server fails to verify that the authenticated user has insert permissions on the destination mailbox — it only checks permissions on the snoozed mailbox. This allows the attacker to specify an arbitrary target mailbox ID (inbox or any other mailbox) as the snooze destination, and the server will deliver mail there without enforcing the appropriate ACL on that target. Exploitation requires network access to the IMAP server, a valid authenticated session, and insert permissions on at least one of the victim's snoozed mailboxes, as well as knowledge of the target mailbox's ID (Red Hat Bugzilla, GitHub Advisory).

Impact

Successful exploitation allows an authenticated attacker to inject arbitrary mail into another user's mailboxes without authorization, violating the integrity of the victim's mailbox. There is no confidentiality or availability impact — the attacker cannot read or delete mail, only insert it. This could be used for phishing, social engineering, or disrupting mail workflows by planting messages in targeted mailboxes (GitHub Advisory, Red Hat Advisory).

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been reported for this vulnerability. The EPSS score is 0.0, indicating very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation requires authentication and specific permissions (insert access to a victim's snoozed mailbox), which significantly limits the attacker pool (GitHub Advisory, Red Hat Advisory).

Exploitation steps

  1. Reconnaissance: Identify a Cyrus IMAP server running a vulnerable version (before 3.8.8, 3.9.0–3.10.3, or 3.11.0–3.12.3) with JMAP enabled.
  2. Obtain credentials: Authenticate to the server with a valid user account that has insert permissions on another user's snoozed mailbox (e.g., via shared mailbox delegation).
  3. Enumerate target mailbox IDs: Use JMAP API calls (e.g., Mailbox/get) to discover the IDs of the victim user's mailboxes, including their inbox.
  4. Craft malicious JMAP snooze request: Construct a JMAP Email/set or snooze-related API call that specifies the victim's target mailbox ID as the snooze destination, bypassing the ACL check on that mailbox.
  5. Trigger mail insertion: Submit the crafted JMAP request; the server processes the snooze operation and delivers the mail to the victim's target mailbox without verifying insert permissions on it (Red Hat Bugzilla, GitHub Advisory).

Indicators of compromise

  • Logs: IMAP/JMAP access logs showing authenticated JMAP snooze or Email/set requests from a user targeting mailboxes belonging to a different user account; unexpected mail delivery events to mailboxes where the sender lacks explicit insert ACL.
  • Mailbox Activity: Unexplained messages appearing in a user's inbox or other mailboxes that were not sent through normal mail flow and originate from a different authenticated user's session.
  • ACL Audit: Discrepancies between ACL-permitted insert targets and actual mailboxes receiving inserted mail, detectable via Cyrus IMAP's mailbox audit logs.

Mitigation and workarounds

Upgrade Cyrus IMAP to one of the patched versions: 3.8.8, 3.10.4, or 3.12.4. Release notes for each fixed version are available on the Cyrus IMAP website. No configuration-based workaround has been published; upgrading to a patched release is the recommended remediation. Administrators should also review and minimize shared mailbox insert permissions as a defense-in-depth measure (Cyrus 3.12.4 Release Notes, Cyrus 3.10.4 Release Notes, Cyrus 3.8.8 Release Notes).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Affected

bookworm

cyrus-imapd

Affected

sid

cyrus-imapd

Affected

trixie

cyrus-imapd

Affected

Ubuntu

Unknown

bionic (esm-apps)

cyrus-imapd

Unknown

devel

cyrus-imapd

Unknown

focal (esm-apps)

cyrus-imapd

Unknown

jammy

cyrus-imapd

Unknown

jammy (esm-apps)

cyrus-imapd

Unknown

noble

cyrus-imapd

Unknown

noble (esm-apps)

cyrus-imapd

Unknown

resolute

cyrus-imapd

Unknown

RHEL / CentOS

Affected

RHEL 8

cyrus-imapd.src

Affected

RHEL 9

cyrus-imapd.src

Affected

RHEL 10

cyrus-imapd.src

Affected

SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-44950CRITICAL9.5
  • Rocky Linux logoRocky Linux
  • libXfont-debuginfo
NoYesSep 10, 2026
CVE-2026-59679CRITICAL9.2
  • Rocky Linux logoRocky Linux
  • libXfont2-doc
NoYesSep 10, 2026
CVE-2026-88924HIGH7
  • Linux Debian logoLinux Debian
  • gvfs-afp
NoNoSep 10, 2026
CVE-2026-87933MEDIUM5.5
  • Linux Debian logoLinux Debian
  • cjson
NoNoSep 10, 2026
CVE-2026-61915MEDIUM4.2
  • Linux Debian logoLinux Debian
  • cyrus-imapd-doc-extra
NoNoSep 09, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management