Bug 2501662 - CVE-2026-47087 cyrus-imapd: Cyrus IMAP: Unauthorized access due to URLAUTH not honoring revoked authorizer access [fedora-all]
Summary: CVE-2026-47087 cyrus-imapd: Cyrus IMAP: Unauthorized access due to URLAUTH no...
Keywords:
Status: ON_QA
Alias: None
Product: Fedora
Classification: Fedora
Component: cyrus-imapd
Version: 45
Hardware: Unspecified
OS: Unspecified
low
low
Target Milestone: ---
Assignee: Martin Osvald 🛹
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: {"flaws": ["d8b448fa-612b-49ca-ae78-6...
Depends On:
Blocks: CVE-2026-47087
TreeView+ depends on / blocked
 
Reported: 2026-07-17 03:40 UTC by Ganesh
Modified: 2026-09-15 02:03 UTC (History)
6 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Ganesh 2026-07-17 03:40:29 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH does not honor revoked authorizer access. A URLAUTH URL minted while the authorizer had access continued to work after that access was revoked.

Comment 1 Aoife Moloney 2026-08-17 15:22:04 UTC
This bug appears to have been reported against 'rawhide' during the Fedora Linux 45 development cycle.
Changing version to 45.

Comment 2 Fedora Update System 2026-09-14 07:16:08 UTC
FEDORA-2026-3bf3e31ef4 (cyrus-imapd-3.12.4-1.fc45) has been submitted as an update to Fedora 45.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-3bf3e31ef4

Comment 3 Fedora Update System 2026-09-14 07:17:38 UTC
FEDORA-2026-740bc1c6fa (cyrus-imapd-3.12.4-1.fc44) has been submitted as an update to Fedora 44.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-740bc1c6fa

Comment 4 Fedora Update System 2026-09-14 07:19:04 UTC
FEDORA-2026-97a7ec5786 (cyrus-imapd-3.10.4-1.fc43) has been submitted as an update to Fedora 43.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-97a7ec5786

Comment 5 Fedora Update System 2026-09-15 01:25:56 UTC
FEDORA-2026-3bf3e31ef4 has been pushed to the Fedora 45 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-3bf3e31ef4`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2026-3bf3e31ef4

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 6 Fedora Update System 2026-09-15 01:41:30 UTC
FEDORA-2026-740bc1c6fa has been pushed to the Fedora 44 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-740bc1c6fa`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2026-740bc1c6fa

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 7 Fedora Update System 2026-09-15 02:03:41 UTC
FEDORA-2026-97a7ec5786 has been pushed to the Fedora 43 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-97a7ec5786`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2026-97a7ec5786

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.


Note You need to log in before you can comment on or make changes to this bug.