CVE-2026-33371

MEDIUM

Zimbra Collaboration 10.0-10.1 - XXE

Title source: llm
STIX 2.1

Description

An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. An XML External Entity (XXE) vulnerability exists in the Zimbra Exchange Web Services (EWS) SOAP interface due to improper handling of XML input. An authenticated attacker can submit crafted XML data that is processed by an XML parser with external entity resolution enabled. Successful exploitation may allow disclosure of sensitive local files from the server.

Scores

CVSS v3 4.3
EPSS 0.0005
EPSS Percentile 16.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-611
Status published
Products (1)
synacor/zimbra_collaboration_suite 10.0.0 - 10.1.16
Published Mar 20, 2026
Tracked Since Mar 20, 2026