CyberRota Analysis
AI-GeneratedAn authorization bypass vulnerability in Zimbra Collaboration prior to version 10.1.17 allows authenticated attackers to exploit the delegated email sending functionality by sending crafted SOAP requests. This enables them to impersonate other users and send emails without the necessary permissions, potentially leading to unauthorized access and information disclosure. Organizations using affected versions of Zimbra should prioritize patching to mitigate this risk.
Original NVD Description
An authorization bypass vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.17 due to improper authorization validation in delegated email sending functionality. An authenticated attacker can send specially crafted SOAP requests to impersonate another user and send emails without possessing the required delegation or send-as permissions. This occurs in the SaveDraftRequest SOAP handler.