nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-47085 CVE-2026-47085
MEDIUM
Cyrus IMAP URLAUTH Token Forgery via Predictable Key
Record summary
CVE-2026-47085 has a selected CVSS score of 4.0 (medium).
Description
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH token forgery can occur via a missing mboxkey. If an attacker knew a folder name on the victim's account for which the victim had never issued an auth URL, they could forge a working URLAUTH token by computing an HMAC-SHA1 value with a predictable key, giving them read access to the mailbox. (URLAUTH is an obscure feature, meaning that the odds of any user actually being susceptible to this attack are very low. Perhaps no public clients use URLAUTH.)
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 16, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Cyrus IMAPBrowse cyrusimap / Cyrus IMAPDefault status: unaffected | CVE List | Before 3.12.3 | affected |
References
3cyrusimap.org
https://www.cyrusimap.org/3.12/imap/download/release-notes/3.12/x/3.12.3.html cyrusimap.org
https://www.cyrusimap.org/imap/download/release-notes/index.html