Policy-Enforcement Flaw in Zimbra Collaboration Suite by Zimbra
CVE-2026-50055

6.5MEDIUM

Key Information:

Vendor

Zimbra

Vendor
CVE Published:
8 October 2026

Badges

📰 News Worthy

What is CVE-2026-50055?

A policy-enforcement flaw in Zimbra Collaboration Suite enables authenticated users to circumvent restrictions on disabled mail forwarding. By utilizing a Sieve notify action, these users can send copies of email content and headers to an arbitrary address, resulting in potential data leakage and unauthorized email sharing.

Affected Version(s)

Zimbra Collaboration Suite 0 < 10.1.20

News Articles

Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities

Zimbra 10.1.20 fixes nine flaws, including SNMP command injection and CVE-2026-50055, which could enable email exfiltration.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • 📰

    First article discovered by The Hacker News

  • Vulnerability Reserved

Credit

Jonah Burgess (CryptoCat), Senior Security Researcher, Rapid7
.