Low severity3.5NVD Advisory· Published Sep 9, 2026· Updated Sep 9, 2026
CVE-2026-61909
CVE-2026-61909
Description
An issue was discovered in Cyrus IMAP before 3.12.4. CalDAV/CardDAV multiget bypasses a per-href ACL. An authenticated DAV user with some shared access to another user's calendar or address book could read even unshared events or contacts by including the target hrefs in a calendar-multiget or addressbook-multiget REPORT.
Affected products
2- Range: <3.12.4
- Range: <3.12.4
Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.