SB2026082146 - Multiple vulnerabilities in Zimbra Collaboration



SB2026082146 - Multiple vulnerabilities in Zimbra Collaboration

Published: August 21, 2026

Security Bulletin ID SB2026082146
CSH Severity
Critical
Patch available
YES
Number of vulnerabilities 9
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Critical 11% Low 89%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 9 vulnerabilities.


1) Cross-site scripting (CVE-ID: N/A)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary script in the victim's browser.

The vulnerability exists due to stored cross-site scripting in the Classic Web Client attachment filename handling when rendering malicious attachment filenames. A remote user can store a crafted attachment filename to execute arbitrary script in the victim's browser.

User interaction is required to render the malicious content under specific conditions.


2) Cross-site scripting (CVE-ID: N/A)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary script in the victim's browser.

The vulnerability exists due to stored cross-site scripting in the Classic Web Client field handling when processing crafted fields. A remote user can store crafted fields to execute arbitrary script in the victim's browser.

The malicious content executes under specific conditions.


3) Cross-site scripting (CVE-ID: N/A)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary script in the victim's browser.

The vulnerability exists due to stored cross-site scripting in the Classic Web Client field rendering when rendering a crafted field. A remote user can store a crafted field to execute arbitrary script in the victim's browser.

User interaction is required to render the malicious content.


4) Cross-site scripting (CVE-ID: N/A)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary script in the victim's browser.

The vulnerability exists due to stored cross-site scripting in the Classic Web Client attachment rendering when rendering crafted attachments. A remote user can store crafted attachments to execute arbitrary script in the victim's browser.

User interaction is required to render the malicious content.


5) Server-Side Request Forgery (SSRF) (CVE-ID: N/A)

CWE-ID: CWE-918 - Server-Side Request Forgery (SSRF)

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to send requests to unintended internal or external resources.

The vulnerability exists due to server-side request forgery in the Nextcloud integration when processing user-supplied resource requests. A remote attacker can submit crafted requests to send requests to unintended internal or external resources.


6) Command injection (CVE-ID: CVE-2026-73570) Exploited

CWE-ID: CWE-77 - Command injection

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary commands.

The vulnerability exists due to command injection in the SNMP monitoring component when SNMP notifications are enabled. A remote attacker can send crafted input to execute arbitrary commands.

Only deployments with SNMP notifications enabled are vulnerable.


7) Improper access control (CVE-ID: CVE-2026-50055)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to exfiltrate email.

The vulnerability exists due to improper access control in mail forwarding restrictions when forwarding mail despite restrictions being enabled. A remote user can bypass forwarding restrictions to exfiltrate email.

Exploitation requires mail forwarding restrictions to be enabled.


8) Improper access control (CVE-ID: CVE-2026-10631)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to bypass access controls.

The vulnerability exists due to improper access control in the EWS extension when handling access-controlled operations. A remote user can perform crafted operations to bypass access controls.


9) Incorrect authorization (CVE-ID: CVE-2026-50054)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to gain unauthorized mailbox access.

The vulnerability exists due to improper authorization in mailbox delegation when processing delegation actions. A remote user can perform crafted delegation actions to gain unauthorized mailbox access.


Remediation

Install update from vendor's website.