CVE-2026-61909

An issue was discovered in Cyrus IMAP before 3.12.4. CalDAV/CardDAV multiget bypasses a per-href ACL. An authenticated DAV user with some shared access to another user's calendar or address book could read even unshared events or contacts by including the target hrefs in a calendar-multiget or addressbook-multiget REPORT.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:cyrus:imap:*:*:*:*:*:*:*:*
cpe:2.3:a:cyrus:imap:*:*:*:*:*:*:*:*
cpe:2.3:a:cyrus:imap:*:*:*:*:*:*:*:*

History

16 Sep 2026, 15:24

Type Values Removed Values Added
CPE cpe:2.3:a:cyrus:imap:*:*:*:*:*:*:*:*
First Time Cyrus
Cyrus imap
References () https://cyrusimap.org - () https://cyrusimap.org - Product
References () https://www.cyrusimap.org/3.12/imap/download/release-notes/3.10/x/3.10.4.html - () https://www.cyrusimap.org/3.12/imap/download/release-notes/3.10/x/3.10.4.html - Release Notes
References () https://www.cyrusimap.org/3.12/imap/download/release-notes/3.12/x/3.12.4.html - () https://www.cyrusimap.org/3.12/imap/download/release-notes/3.12/x/3.12.4.html - Release Notes
References () https://www.cyrusimap.org/3.12/imap/download/release-notes/3.8/x/3.8.8.html - () https://www.cyrusimap.org/3.12/imap/download/release-notes/3.8/x/3.8.8.html - Release Notes

Information

Published : 2026-09-09 20:18

Updated : 2026-09-16 15:24


NVD link : CVE-2026-61909

Mitre link : CVE-2026-61909

CVE.ORG link : CVE-2026-61909


JSON object : View

Products Affected

cyrus

  • imap
CWE
CWE-420

Unprotected Alternate Channel