← Back

CVE-2026-73570

nvd nist
Published: Aug 13, 2026Modified: Aug 22, 2026CISA KEV

JSON object

Loading...
8.9
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L
Exploitability: 2.2 / Impact: 6.0
Source: MITRE (Secondary)

Description

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.

Affected (1)

1 product
Zimbra Collaboration Suite
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 10.1.20

References (4)

Source: cve@mitre.org
Release Notes
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

Timeline

No history available yet.