{"id":"CVE-2026-61911","title":"An issue was discovered in Cyrus IMAP before 3.12.4","summary":"An issue was discovered in Cyrus IMAP before 3.12.4. There is a Sieve mailbox existence oracle. An authenticated user could install a Sieve script that probed whether another user's private mailbox existed, or read the value of shared ma…","severity":"medium","cvss":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","cwe":["CWE-497"],"vendor":"cyrus","product":"imap","affected":["imap < 3.8.8","imap >= 3.9.0, < 3.10.4","imap >= 3.11.0, < 3.12.4"],"patched":["imap 3.12.4"],"published":"2026-09-09","updated":"2026-09-16","sourceUpdated":"2026-09-16T15:23:58.500","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-61911","references":[{"url":"https://cyrusimap.org","label":"cve@mitre.org"},{"url":"https://www.cyrusimap.org/3.12/imap/download/release-notes/3.10/x/3.10.4.html","label":"cve@mitre.org"},{"url":"https://www.cyrusimap.org/3.12/imap/download/release-notes/3.12/x/3.12.4.html","label":"cve@mitre.org"},{"url":"https://www.cyrusimap.org/3.12/imap/download/release-notes/3.8/x/3.8.8.html","label":"cve@mitre.org"}],"tags":["nvd","cve.org"],"epss":0.00373,"epssPercentile":0.2852,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-10T18:59:21.694757Z"},"ingestedAt":"2026-09-11T17:50:33.677Z","slug":"CVE-2026-61911","body":"## Overview\n\nAn issue was discovered in Cyrus IMAP before 3.12.4. There is a Sieve mailbox existence oracle. An authenticated user could install a Sieve script that probed whether another user's private mailbox existed, or read the value of shared mailbox annotations, by observing which fileinto branch fired during LMTP delivery.\n\n## Affected\n\n- `imap < 3.8.8`\n- `imap >= 3.9.0, < 3.10.4`\n- `imap >= 3.11.0, < 3.12.4`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `imap 3.12.4`","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":23.7,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}