CVE-2026-61910
Publication date 9 September 2026
Last updated 11 September 2026
Ubuntu priority
Cvss 3 Severity Score
Description
Mailbox/set let sharee change special-use role on shared mailboxes: An authenticated user with maySetKeywords on another user's mailbox could change that mailbox's specialuse annotation. This could allow the sharee to change the shared mailbox to perform the archived, snoozed, or other role, which might cause mail to be written to the shared mailbox, sharing more content than intended. This is likely to be an unusual situation, made more unusual because if the target already has an non-shared mailbox with that role, role duplication suppression will prevent the update.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| cyrus-imapd | 26.04 LTS resolute |
Needs evaluation
|
| 24.04 LTS noble |
Needs evaluation
|
|
| 22.04 LTS jammy |
Needs evaluation
|
|
| 20.04 LTS focal |
Needs evaluation
|
|
| 18.04 LTS bionic |
Needs evaluation
|
Notes
mrmajumder
Vendor patch for versions 3.8, 3.10 and 3.12 stored in the embargoed repository at fixes/cyrus-imapd/patches-<version>/CVE-2026-61910.patch. For versions older than 3.8, the 3.8 patches might need to be backported
Severity score breakdown
CVSS version: CVSS v3.0
Base score
3.5 · Low
Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N