An authorization bypass vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.17 due to improper authorization validation in delegated email sending functionality. An authenticated attacker can send specially crafted SOAP requests to impersonate another user and send emails without possessing the required delegation or send-as permissions. This occurs in the SaveDraftRequest SOAP handler.
References
| Link | Resource |
|---|---|
| https://wiki.zimbra.com/wiki/Security_Center | Vendor Advisory |
| https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-08-13 16:19
Updated : 2026-08-28 13:58
NVD link : CVE-2026-73571
Mitre link : CVE-2026-73571
CVE.ORG link : CVE-2026-73571
JSON object : View
Products Affected
synacor
- zimbra_collaboration_suite
CWE
CWE-863
Incorrect Authorization
