Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4355 articles · 196337 vulns · 36/41 feeds (7d)
← Back to list
3.1
CVE-2026-73571PATCHED
Zimbra · Collaboration

CVE-2026-73571: An authorization bypass vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.17 due to improper authorization

Description

An authorization bypass vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.17 due to improper authorization validation in delegated email sending functionality. An authenticated attacker can send specially crafted SOAP requests to impersonate another user and send emails without possessing the required delegation or send-as permissions. This occurs in the SaveDraftRequest SOAP handler.

Affected Products

VendorProductVersions
ZimbraCollaboration0

References

  • https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories
  • https://wiki.zimbra.com/wiki/Security_Center

Related News (1 articles)

Tier C
VulDB10d ago
CVE-2026-73571 | Zimbra Collaboration up to 10.1.16 SaveDraftRequest SOAP authorization
→ No new info (linked only)
CVSS 3.13.1 LOW
VectorCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available
10.1.17
CWECWE-863
PublishedAug 13, 2026
Last enriched10d ago
Trending Score5
Source articles1
Independent1
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

LOWCVE-2026-73574
CVE-2026-73574: In Zimbra Collaboration before 10.1.17, a local file inclusion (LFI) vulnerability exists in the Zimbra Classic Web Clie
Trending: 8
LOWCVE-2026-73575
CVE-2026-73575: In Zimbra Collaboration (ZCS) before 10.1.17, a Cross-Site Request Forgery (CSRF) vulnerability exists in the Exchange W
Trending: 5
LOWCVE-2026-73573
CVE-2026-73573: In Zimbra Collaboration (ZCS) before 10.1.17, a path traversal vulnerability exists in the Zimbra Briefcase document edi
Trending: 5
MEDIUMCVE-2026-73576
CVE-2026-73576: In Zimbra Collaboration (ZCS) before 10.1.17, weak cryptographic key generation vulnerability exists in the OnlyOffice i
Trending: 5
MEDIUMCVE-2026-73572
CVE-2026-73572: In Zimbra Collaboration (ZCS) before 10.1.17, a stored cross-site scripting (XSS) vulnerability exists in the Zimbra Cla
Trending: 5

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 13, 2026
Discovered by ZDM
Aug 13, 2026
Patch Available
Aug 13, 2026