SB2026082146 - Multiple vulnerabilities in Zimbra Collaboration
Published: August 21, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 9 vulnerabilities.
1) Cross-site scripting (CVE-ID: N/A)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote user to execute arbitrary script in the victim's browser.
The vulnerability exists due to stored cross-site scripting in the Classic Web Client attachment filename handling when rendering malicious attachment filenames. A remote user can store a crafted attachment filename to execute arbitrary script in the victim's browser.
User interaction is required to render the malicious content under specific conditions.
2) Cross-site scripting (CVE-ID: N/A)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote user to execute arbitrary script in the victim's browser.
The vulnerability exists due to stored cross-site scripting in the Classic Web Client field handling when processing crafted fields. A remote user can store crafted fields to execute arbitrary script in the victim's browser.
The malicious content executes under specific conditions.
3) Cross-site scripting (CVE-ID: N/A)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote user to execute arbitrary script in the victim's browser.
The vulnerability exists due to stored cross-site scripting in the Classic Web Client field rendering when rendering a crafted field. A remote user can store a crafted field to execute arbitrary script in the victim's browser.
User interaction is required to render the malicious content.
4) Cross-site scripting (CVE-ID: N/A)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote user to execute arbitrary script in the victim's browser.
The vulnerability exists due to stored cross-site scripting in the Classic Web Client attachment rendering when rendering crafted attachments. A remote user can store crafted attachments to execute arbitrary script in the victim's browser.
User interaction is required to render the malicious content.
5) Server-Side Request Forgery (SSRF) (CVE-ID: N/A)
CWE-ID: CWE-918 - Server-Side Request Forgery (SSRF)
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to send requests to unintended internal or external resources.
The vulnerability exists due to server-side request forgery in the Nextcloud integration when processing user-supplied resource requests. A remote attacker can submit crafted requests to send requests to unintended internal or external resources.
6) Command injection (CVE-ID: CVE-2026-73570) Exploited
CWE-ID: CWE-77 - Command injection
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary commands.
The vulnerability exists due to command injection in the SNMP monitoring component when SNMP notifications are enabled. A remote attacker can send crafted input to execute arbitrary commands.
Only deployments with SNMP notifications enabled are vulnerable.
7) Improper access control (CVE-ID: CVE-2026-50055)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to exfiltrate email.
The vulnerability exists due to improper access control in mail forwarding restrictions when forwarding mail despite restrictions being enabled. A remote user can bypass forwarding restrictions to exfiltrate email.
Exploitation requires mail forwarding restrictions to be enabled.
8) Improper access control (CVE-ID: CVE-2026-10631)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to bypass access controls.
The vulnerability exists due to improper access control in the EWS extension when handling access-controlled operations. A remote user can perform crafted operations to bypass access controls.
9) Incorrect authorization (CVE-ID: CVE-2026-50054)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to gain unauthorized mailbox access.
The vulnerability exists due to improper authorization in mailbox delegation when processing delegation actions. A remote user can perform crafted delegation actions to gain unauthorized mailbox access.
Remediation
Install update from vendor's website.