Reflected Cross-Site Scripting Vulnerability in Zimbra Collaboration Suite
CVE-2026-33368

6.1MEDIUM

Key Information:

Vendor

Zimbra

Vendor
CVE Published:
20 March 2026

What is CVE-2026-33368?

The Zimbra Collaboration Suite (ZCS) versions 10.0 and 10.1 contain a reflected XSS vulnerability in the Classic Webmail REST interface. This vulnerability arises from insufficient sanitization of user-supplied input, enabling an unauthenticated attacker to craft a malicious URL that, when accessed by a victim user, executes injected JavaScript within the context of the Zimbra webmail application. This can lead to unauthorized actions performed on behalf of the victim, posing significant security risks.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.