Bug 2526311 (CVE-2026-61910) - CVE-2026-61910 cyrus-imapd: cyrus-imapd: Mailbox/set let sharee change special-use role on shared mailboxes
Summary: CVE-2026-61910 cyrus-imapd: cyrus-imapd: Mailbox/set let sharee change specia...
Keywords:
Status: NEW
Alias: CVE-2026-61910
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2531317
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-31 14:14 UTC by OSIDB Bzimport
Modified: 2026-09-10 08:37 UTC (History)
3 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-08-31 14:14:22 UTC
An authenticated user with maySetKeywords on another user's mailbox could change that mailbox's specialuse annotation.  This could allow the sharee to change the shared mailbox to perform the archived, snoozed, or other role, which might cause mail mail to be written to the shared mailbox, sharing more content than intended.

This is likely to be an unusual situation, made more unusual because if the target already has an non-shared mailbox with that role, role duplication suppression will prevent the update.


Note You need to log in before you can comment on or make changes to this bug.