Zimbra Collaboration(ZCS)10.1.17 之前的版本中存在一个授权绕过漏洞,该漏洞源于委派邮件发送功能中的授权验证不当。经过身份验证的攻击者可以通过发送精心构造的 SOAP 请求,冒充其他用户发送邮件,而无需具备所需的委派权限或“以该用户身份发送邮件”(send-as)权限。此漏洞存在于 SaveDraftRequest SOAP 处理程序中。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Zimbra | Collaboration | < 10.1.17 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Zimbra | Collaboration | 0 ~ 10.1.17 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-73570 | 8.9 HIGH | Zimbra Collaboration 命令注入漏洞 |
| CVE-2026-73576 | 6.3 MEDIUM | Zimbra <10.1.17 OnlyOffice弱密钥生成致JWT伪造 |
| CVE-2026-73572 | 6.1 MEDIUM | Zimbra <10.1.17 存储型XSS漏洞 |
| CVE-2026-73575 | 3.1 LOW | ZCS<10.1.17 CSRF漏洞 |
| CVE-2026-73573 | 3.1 LOW | Zimbra Collaboration <10.1.17 路径穿越漏洞 |
| CVE-2026-73574 | 3.1 LOW | Zimbra<10.1.17经典Web客户端LFI漏洞 |
No comments yet