AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2018-10949

MEDIUM · CVSS 5.3 EPSS 2.45%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2018-05-10 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2018-10949
Severity
MEDIUM
CVSS
5.3
EPSS
2.45%

Original NVD Description

mailboxd in Zimbra Collaboration Suite 8.8 before 8.8.8; 8.7 before 8.7.11.Patch3; and 8.6 allows Account Enumeration by leveraging a Discrepancy between the "HTTP 404 - account is not active" and "HTTP 401 - must authenticate" errors.