CVE-2026-61907
Publication date 9 September 2026
Last updated 10 September 2026
Ubuntu priority
Description
JMAP snooze bypasses destination-mailbox ACL: An authenticated user with insert permissions on another user's snoozed mailbox could cause insertion of mail to that user's inbox, or any other of their mailboxes whose id was known to the user, despite having no insert permissions to the target mailbox.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| cyrus-imapd | 26.04 LTS resolute |
Needs evaluation
|
| 24.04 LTS noble |
Needs evaluation
|
|
| 22.04 LTS jammy |
Needs evaluation
|
|
| 20.04 LTS focal |
Needs evaluation
|
|
| 18.04 LTS bionic |
Needs evaluation
|
Notes
mrmajumder
Vendor patch for versions 3.8, 3.10 and 3.12 stored in the embargoed repository at fixes/cyrus-imapd/patches-<version>/CVE-2026-61907.patch. For versions older than 3.8, the 3.8 patches might need to be backported