SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-61909

LOW · CVSS 3.5 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-09-09 · Last synced 2026-09-13

CyberRota Analysis

AI-Generated

Cyrus IMAP versions prior to 3.12.4 are vulnerable to a CalDAV/CardDAV multiget bypass, allowing authenticated users with limited access to read unshared calendar events or contacts by manipulating target hrefs in specific REPORT requests. This could lead to unauthorized data exposure, impacting user privacy. Organizations using affected versions should prioritize patching to mitigate potential information leakage.

CVE
CVE-2026-61909
Severity
LOW
CVSS
3.5
EPSS
0.20%

Original NVD Description

An issue was discovered in Cyrus IMAP before 3.12.4. CalDAV/CardDAV multiget bypasses a per-href ACL. An authenticated DAV user with some shared access to another user's calendar or address book could read even unshared events or contacts by including the target hrefs in a calendar-multiget or addressbook-multiget REPORT.