CVE-2026-61911
An issue was discovered in Cyrus IMAP before 3.12.4. There is a Sieve mailbox existence oracle. An authenticated user could install a Sieve
CVSS
4.3
Medio
EPSS
—
KEV
—
Exploit Today
—
0-100
Publicado: 9 sept 2026 · Última mod.: 10 sept 2026 · CWE-497
Sin historial EPSS suficiente todavía.
An issue was discovered in Cyrus IMAP before 3.12.4. There is a Sieve mailbox existence oracle. An authenticated user could install a Sieve script that probed whether another user's private mailbox existed, or read the value of shared mailbox annotations, by observing which fileinto branch fired during LMTP delivery.
- cyrusimap.orghttps://cyrusimap.org
- www.cyrusimap.orghttps://www.cyrusimap.org/3.12/imap/download/release-notes/3.10/x/3.10.4.html
- www.cyrusimap.orghttps://www.cyrusimap.org/3.12/imap/download/release-notes/3.12/x/3.12.4.html
- www.cyrusimap.orghttps://www.cyrusimap.org/3.12/imap/download/release-notes/3.8/x/3.8.8.html
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-813945.5 MED33.6%
——10Exposure of sensitive system information to an unauthorized control sphere in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.2dCVE-2026-813875.5 MED35.3%
——11Exposure of sensitive system information to an unauthorized control sphere in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.2dCVE-2026-713307.5 ALT54.0%
——16Exposure of sensitive system information to an unauthorized control sphere in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to disclose information over a network.2dCVE-2026-698325.6 MED31.3%
——9Exposure of sensitive system information to an unauthorized control sphere in Windows Win32K allows an authorized attacker to disclose information locally.2dCVE-2026-697235.7 MED60.6%
——18Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an authorized attacker to disclose information over a network.2dCVE-2026-694065.5 MED41.3%
——12Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an authorized attacker to disclose information locally.2d