← Back

CVE-2026-73571

nvd nist
Published: Aug 13, 2026Modified: Aug 28, 2026

JSON object

Loading...
4.3
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Exploitability: 2.8 / Impact: 1.4
Source: NVD

Description

An authorization bypass vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.17 due to improper authorization validation in delegated email sending functionality. An authenticated attacker can send specially crafted SOAP requests to impersonate another user and send emails without possessing the required delegation or send-as permissions. This occurs in the SaveDraftRequest SOAP handler.

Affected (1)

1 product
Zimbra Collaboration Suite
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 10.1.17

References (2)

Source: cve@mitre.org
Vendor Advisory

Timeline

No history available yet.