In Zimbra Collaboration before 10.1.17, a local file inclusion (LFI) vulnerability exists in the Zimbra Classic Web Client due to improper validation of the fu request parameter. An unauthenticated attacker can exploit this vulnerability by supplying a crafted path, potentially allowing unauthorized disclosure of protected files, such as WEB-INF/web.xml, within the web application directory. This occurs in the Forward servlet.
References
| Link | Resource |
|---|---|
| https://wiki.zimbra.com/wiki/Zimbra_Responsible_Disclosure_Policy | Vendor Advisory |
| https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-08-13 16:19
Updated : 2026-08-28 13:49
NVD link : CVE-2026-73574
Mitre link : CVE-2026-73574
CVE.ORG link : CVE-2026-73574
JSON object : View
Products Affected
synacor
- zimbra_collaboration_suite
CWE
CWE-669
Incorrect Resource Transfer Between Spheres
