CVE-2026-47087EPSS p19.3%

CVE-2026-47087CVE-2026-47087

Description

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH does not honor revoked authorizer access. A URLAUTH URL minted while the authorizer had access continued to work after that access was revoked.

Scoring

CVSS 3.5 ()
VectorCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N
EPSS0.29% probability of exploitation · percentile 19.3% · 2026-10-06T12:00:23Z
Last modified2026-07-17
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.