Policy-Enforcement Flaw in Zimbra Collaboration Suite by Zimbra
CVE-2026-50055
6.5MEDIUM
What is CVE-2026-50055?
A policy-enforcement flaw in Zimbra Collaboration Suite enables authenticated users to circumvent restrictions on disabled mail forwarding. By utilizing a Sieve notify action, these users can send copies of email content and headers to an arbitrary address, resulting in potential data leakage and unauthorized email sharing.
Affected Version(s)
Zimbra Collaboration Suite 0 < 10.1.20
News Articles
Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities
Zimbra 10.1.20 fixes nine flaws, including SNMP command injection and CVE-2026-50055, which could enable email exfiltration.
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
- 📰
First article discovered by The Hacker News
Vulnerability Reserved
Credit
Jonah Burgess (CryptoCat), Senior Security Researcher, Rapid7
