CVE-2026-73571

An authorization bypass vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.17 due to improper authorization validation in delegated email sending functionality. An authenticated attacker can send specially crafted SOAP requests to impersonate another user and send emails without possessing the required delegation or send-as permissions. This occurs in the SaveDraftRequest SOAP handler.
Configurations

Configuration 1 (hide)

cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-08-13 16:19

Updated : 2026-08-28 13:58


NVD link : CVE-2026-73571

Mitre link : CVE-2026-73571

CVE.ORG link : CVE-2026-73571


JSON object : View

Products Affected

synacor

  • zimbra_collaboration_suite
CWE
CWE-863

Incorrect Authorization