在 Zimbra Collaboration Suite 10.1.0 至 10.1.19 版本的 EWS(Exchange Web Services)FindItem 处理程序中存在授权绕过漏洞。该漏洞允许启用了 EWS 的认证用户,在没有共享或委托授权的情况下,读取任意本地账户的完整邮箱项目,包括原始 MIME 内容和附件。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Zimbra | Zimbra Collaboration Suite | < 10.1.20 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Zimbra | Zimbra Collaboration Suite | 0 ~ 10.1.20 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-50054 | 7.1 HIGH | Zimbra Collaboration Suite GrantRightsRequest SOAP Handler Allows Self-Granting of Undocum |
| CVE-2026-50055 | 6.5 MEDIUM | Zimbra Collaboration Suite Sieve Notify Filter Action Bypasses Mail Forwarding Restriction |
No comments yet