vulnti.work

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an XAPPLEPUSHSERVICE folder existence oracle and push hijack. An authenticated IMAP user could probe for the existence of…

Low CVSS 3.1
CVECVE-2026-47081
First seen2026-07-17 19:16 UTC
Disclosed2026-07-16 19:16 UTC
Last updated2026-07-17 19:16 UTC
Channel statusauto

Summary

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an XAPPLEPUSHSERVICE folder existence oracle and push hijack. An authenticated IMAP user could probe for the existence of arbitrary mailboxes on other users' accounts via the XAPPLEPUSHSERVICE command and then create Apple Push Notification Service notifications for new mail in those mailboxes to their own APNS device. This did not leak any data about the content of mailboxes. Instead, a "mailbox has changed" notice w…

In-depth triage · Auto channel

No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).

Lint boundary warnings (2)

The following non-blocking warnings were raised during the lint phase of this triage (e.g. reference URLs not yet on the allowlist). They do not affect entry usability and are disclosed for transparency (see DR-002).

  • REF_URL_NOT_ALLOWLISTED url not in allowlist: https://www.cyrusimap.org/3.12/imap/download/release-notes/3.12/x/3.12.3.html
  • REF_URL_NOT_ALLOWLISTED url not in allowlist: https://www.cyrusimap.org/imap/download/release-notes/index.html

Sources

  • NVD DATABASE

Original Links

Timeline

  1. nvd_ingest NVD