CVE-2026-61909: Cyrus Imap

Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.

An issue was discovered in Cyrus IMAP before 3.12.4. CalDAV/CardDAV multiget bypasses a per-href ACL. An authenticated DAV user with some shared access to another user's calendar or address book could read even unshared events or contacts by including the target hrefs in a calendar-multiget or addressbook-multiget REPORT.

Affected products

  • Cyrus Imap: before 3.8.8 (fixed in 3.8.8); from 3.9.0, before 3.10.4 (fixed in 3.10.4); from 3.11.0, before 3.12.4 (fixed in 3.12.4)

Published 2026-09-09. Last modified 2026-09-16.