AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-73571

LOW · CVSS 3.1 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-08-13 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

An authorization bypass vulnerability in Zimbra Collaboration prior to version 10.1.17 allows authenticated attackers to exploit the delegated email sending functionality by sending crafted SOAP requests. This enables them to impersonate other users and send emails without the necessary permissions, potentially leading to unauthorized access and information disclosure. Organizations using affected versions of Zimbra should prioritize patching to mitigate this risk.

CVE
CVE-2026-73571
Severity
LOW
CVSS
3.1
EPSS
0.17%

Original NVD Description

An authorization bypass vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.17 due to improper authorization validation in delegated email sending functionality. An authenticated attacker can send specially crafted SOAP requests to impersonate another user and send emails without possessing the required delegation or send-as permissions. This occurs in the SaveDraftRequest SOAP handler.