Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in Zimbra Collaboration - #VU134811
Published: June 18, 2026
Zimbra Collaboration
Detailed vulnerability description
The vulnerability allows a remote attacker to brute-force the JWT signing secret offline.
The vulnerability exists due to use of a weak pseudo-random number generator in zimbraDocumentEditingJwtSecret generation when creating the JWT signing secret. A remote attacker can perform offline guessing attacks to brute-force the JWT signing secret.