CVE-2026-61909
EUVD-2026-7513209.09.2026, 20:18
An issue was discovered in Cyrus IMAP before 3.12.4. CalDAV/CardDAV multiget bypasses a per-href ACL. An authenticated DAV user with some shared access to another user's calendar or address book could read even unshared events or contacts by including the target hrefs in a calendar-multiget or addressbook-multiget REPORT.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| cyrusimap | cyrus_imap | 𝑥 < 3.8.8 | CNA |
| cyrusimap | cyrus_imap | 3.9.0 ≤ 𝑥 < 3.10.4 | CNA |
| cyrusimap | cyrus_imap | 3.11.0 ≤ 𝑥 < 3.12.4 | CNA |
Common Weakness Enumeration