DEBIAN-CVE-2026-61910

Source
https://security-tracker.debian.org/tracker/CVE-2026-61910
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-61910.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-61910
Upstream
Published
2026-09-09T20:18:36Z
Modified
2026-09-17T09:00:11Z
Severity
  • 5.0 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N CVSS Calculator
Summary
[none]
Details

An issue was discovered in Cyrus IMAP before 3.12.4. Mailbox/set let a sharee change a special-use role on shared mailboxes. An authenticated user with maySetKeywords on another user's mailbox could change that mailbox's specialuse annotation. This could allow the sharee to change the shared mailbox to perform the archived, snoozed, or other role, which might cause mail mail to be written to the shared mailbox, sharing more content than intended. (This is likely to be an unusual situation, made more unusual because if the target already has an non-shared mailbox with that role, role duplication suppression will prevent the update.)

References

Affected packages

Debian:12 / cyrus-imapd

Package

Name
cyrus-imapd
Purl
pkg:deb/debian/cyrus-imapd?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.6.1-4
3.6.1-4+deb12u1
3.6.1-4+deb12u2
3.6.1-4+deb12u3
3.6.1-4+deb12u4
3.6.1-4+deb12u5
3.8.0~beta1-1
3.8.0~beta2-1
3.8.0~rc1-1
3.8.0-1
3.8.0-2
3.8.0-3
3.8.0-4
3.8.0-5
3.8.1-1~bpo12+1
3.8.1-1
3.8.1-2
3.8.1-3
3.8.2-1
3.8.3-1
3.8.4-1
3.10.0~beta1-1
3.10.0~beta1-2
3.10.0~beta1-3
3.10.0~beta2-1
3.10.0~rc2-1
3.10.0-1
3.10.1-1
3.10.1-2
3.10.1-3~bpo12+1
3.10.1-3
3.10.2-1~bpo12+1
3.10.2-1
3.12.0-1
3.12.0-2
3.12.1-1
3.12.1-2
3.12.1-3
3.12.2-1
3.12.3-1~bpo13+1
3.12.3-1
3.12.3-2
3.12.3-3
3.12.3-4
3.12.4-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-61910.json"

Debian:13 / cyrus-imapd

Package

Name
cyrus-imapd
Purl
pkg:deb/debian/cyrus-imapd?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.10.2-1
3.10.2-1+deb13u1
3.10.2-1+deb13u2
3.12.0-1
3.12.0-2
3.12.1-1
3.12.1-2
3.12.1-3
3.12.2-1
3.12.3-1~bpo13+1
3.12.3-1
3.12.3-2
3.12.3-3
3.12.3-4
3.12.4-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-61910.json"

Debian:14 / cyrus-imapd

Package

Name
cyrus-imapd
Purl
pkg:deb/debian/cyrus-imapd?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.12.4-1

Affected versions

3.*
3.10.2-1
3.12.0-1
3.12.0-2
3.12.1-1
3.12.1-2
3.12.1-3
3.12.2-1
3.12.3-1~bpo13+1
3.12.3-1
3.12.3-2
3.12.3-3
3.12.3-4

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-61910.json"