Zimbra Collaboration Suite 中 GrantRightsRequest 存在一个授权缺陷,允许已认证账户的攻击者将 loginAs 权限授予其他本地账户,从而创建持久的邮箱访问权限和邮件发送权限,即使在密码更改或会话过期后这些权限仍然有效。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Zimbra | Zimbra Collaboration Suite | < 10.1.20 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Zimbra | Zimbra Collaboration Suite | 0 ~ 10.1.20 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-10631 | 6.5 MEDIUM | Zimbra Collaboration Suite EWS Extension Authorization Bypass via Crafted Composite Folder |
| CVE-2026-50055 | 6.5 MEDIUM | Zimbra Collaboration Suite Sieve Notify Filter Action Bypasses Mail Forwarding Restriction |
No comments yet