Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in Zimbra Collaboration - #VU134811
Published: June 18, 2026
Vulnerability details
The vulnerability allows a remote attacker to brute-force the JWT signing secret offline.
The vulnerability exists due to use of a weak pseudo-random number generator in zimbraDocumentEditingJwtSecret generation when creating the JWT signing secret. A remote attacker can perform offline guessing attacks to brute-force the JWT signing secret.