CVE-2026-61911: Cyrus Imap
Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.
An issue was discovered in Cyrus IMAP before 3.12.4. There is a Sieve mailbox existence oracle. An authenticated user could install a Sieve script that probed whether another user's private mailbox existed, or read the value of shared mailbox annotations, by observing which fileinto branch fired during LMTP delivery.
Affected products
- Cyrus Imap: before 3.8.8 (fixed in 3.8.8); from 3.9.0, before 3.10.4 (fixed in 3.10.4); from 3.11.0, before 3.12.4 (fixed in 3.12.4)
Published 2026-09-09. Last modified 2026-09-16.