Zimbra Collaboration Suite 中存在一个策略执行缺陷,允许经过身份验证的用户绕过已禁用的邮件转发功能。该用户可利用 Sieve notify 动作,将电子邮件的内容和标头副本发送到任意指定地址。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Zimbra | Zimbra Collaboration Suite | < 10.1.20 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Zimbra | Zimbra Collaboration Suite | 0 ~ 10.1.20 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-50054 | 7.1 HIGH | Zimbra Collaboration Suite GrantRightsRequest SOAP Handler Allows Self-Granting of Undocum |
| CVE-2026-10631 | 6.5 MEDIUM | Zimbra Collaboration Suite EWS Extension Authorization Bypass via Crafted Composite Folder |
No comments yet