nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-73575 CVE-2026-73575
LOW
Zimbra Collaboration Exchange Web Services Endpoint Cross-Site Request Forgery
Record summary
CVE-2026-73575 has a selected CVSS score of 3.1 (low).
Description
In Zimbra Collaboration (ZCS) before 10.1.17, a Cross-Site Request Forgery (CSRF) vulnerability exists in the Exchange Web Services (EWS) endpoint of Zimbra Collaboration (ZCS) due to insufficient validation of request content types. An attacker can exploit this vulnerability by causing an authenticated user to submit a crafted request, potentially allowing unauthorized actions to be performed on behalf of the victim.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 13, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
CollaborationBrowse Zimbra / CollaborationDefault status: unaffected | CVE List | Before 10.1.17 | affected |
References
3wiki.zimbra.com
https://wiki.zimbra.com/wiki/Zimbra_Responsible_Disclosure_Policy wiki.zimbra.com
https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories