Vulnerability Description
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an XAPPLEPUSHSERVICE folder existence oracle and push hijack. An authenticated IMAP user could probe for the existence of arbitrary mailboxes on other users' accounts via the XAPPLEPUSHSERVICE command and then create Apple Push Notification Service notifications for new mail in those mailboxes to their own APNS device. This did not leak any data about the content of mailboxes. Instead, a "mailbox has changed" notice would be pushed when the mailbox modseq changed.
CVSS Score
LOW
Related Weaknesses (CWE)
References
- https://www.cyrusimap.org/3.12/imap/download/release-notes/3.12/x/3.12.3.html
- https://www.cyrusimap.org/imap/download/release-notes/index.html
FAQ
What is CVE-2026-47081?
CVE-2026-47081 is a vulnerability with a CVSS score of 3.1 (LOW). An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an XAPPLEPUSHSERVICE folder existence oracle and push hijack. An authenticated IMAP user could probe for the existence of ...
How severe is CVE-2026-47081?
CVE-2026-47081 has been rated LOW with a CVSS base score of 3.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-47081?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.