Email Spoofing Vulnerability in Zimbra Collaboration
CVE-2023-26562
6.5MEDIUM
What is CVE-2023-26562?
A security issue affects Zimbra Collaboration Suite (ZCS) versions 8.8.15 and 9.0, whereby closed accounts that have two-factor authentication (2FA) enabled and use generated passwords are able to send email messages. This flaw can lead to unauthorized email transmissions, posing risks for organizations and individuals relying on Zimbra's email services. The vulnerability allows for potential misuse of these closed accounts, making it critical for users to ensure appropriate security measures are in place and to monitor for any unauthorized activity.