A vulnerability labeled as very critical has been found in cyrusimap Cyrus IMAP up to 3.12.2. Affected is an unknown function of the component ACL. The manipulation results in permission issues.
This vulnerability is known as CVE-2026-47084. It is possible to launch the attack remotely. No exploit is available.