XML External Entity Vulnerability in Zimbra Collaboration by Zimbra
CVE-2026-33371

4.3MEDIUM

Key Information:

Vendor

Zimbra

Vendor
CVE Published:
20 March 2026

What is CVE-2026-33371?

An XML External Entity (XXE) vulnerability has been identified in Zimbra Collaboration Suite 10.0 and 10.1, arising from inadequate handling of XML input within the Zimbra Exchange Web Services (EWS) SOAP interface. This vulnerability permits an authenticated attacker to send specially crafted XML data, which is then processed by an XML parser with external entity resolution enabled. Exploiting this flaw can lead to the exposure of sensitive local files stored on the server, posing a significant risk to data integrity and confidentiality.

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.