VYPR
Low severity3.5NVD Advisory· Published Jul 16, 2026· Updated Jul 17, 2026

CVE-2026-47087

CVE-2026-47087

Description

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH does not honor revoked authorizer access. A URLAUTH URL minted while the authorizer had access continued to work after that access was revoked.

Affected products

2

Patches

Vulnerability mechanics

References

2

News mentions

1