Improper access control in Zimbra Collaboration - CVE-2026-50055
Published: August 21, 2026
Vulnerability details
The vulnerability allows a remote user to exfiltrate email.
The vulnerability exists due to improper access control in mail forwarding restrictions when forwarding mail despite restrictions being enabled. A remote user can bypass forwarding restrictions to exfiltrate email.
Exploitation requires mail forwarding restrictions to be enabled.