← Πίσω στην αναζήτηση CVE

CVE-2026-47082

cyrus-imapd

Περιγραφή

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. The vacation -fcc- feature skips the destination-mailbox ACL. A user whose vacation Sieve script used :fcc (to save a copy of the sent message) could deliver vacation auto-reply copies into any mailbox the script could name, regardless of whether the script owner had insert permissions on the destination mailbox.

CVSS 5.4EPSS 0.196%Κίνδυνος 0.55
Προβολή πηγής
Δημοσίευση
2026-07-16 19:16:48
Επηρεαζόμενες εκδόσεις
<=3.12.2
Τύπος
Κρίσιμο λογισμικό
Διάνυσμα
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L