An issue was discovered in Cyrus IMAP before 3.12.4. CalDAV/CardDAV multiget bypasses a per-href ACL. An authenticated DAV user with some shared access to another user's calendar or address book could read even unshared events or contacts by including the target hrefs in a calendar-multiget or addressbook-multiget REPORT.
References
| Link | Resource |
|---|---|
| https://cyrusimap.org | Product |
| https://www.cyrusimap.org/3.12/imap/download/release-notes/3.10/x/3.10.4.html | Release Notes |
| https://www.cyrusimap.org/3.12/imap/download/release-notes/3.12/x/3.12.4.html | Release Notes |
| https://www.cyrusimap.org/3.12/imap/download/release-notes/3.8/x/3.8.8.html | Release Notes |
Configurations
Configuration 1 (hide)
|
History
16 Sep 2026, 15:24
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:cyrus:imap:*:*:*:*:*:*:*:* | |
| First Time |
Cyrus
Cyrus imap |
|
| References | () https://cyrusimap.org - Product | |
| References | () https://www.cyrusimap.org/3.12/imap/download/release-notes/3.10/x/3.10.4.html - Release Notes | |
| References | () https://www.cyrusimap.org/3.12/imap/download/release-notes/3.12/x/3.12.4.html - Release Notes | |
| References | () https://www.cyrusimap.org/3.12/imap/download/release-notes/3.8/x/3.8.8.html - Release Notes |
Information
Published : 2026-09-09 20:18
Updated : 2026-09-16 15:24
NVD link : CVE-2026-61909
Mitre link : CVE-2026-61909
CVE.ORG link : CVE-2026-61909
JSON object : View
Products Affected
cyrus
- imap
CWE
CWE-420
Unprotected Alternate Channel
