Remote Code Execution in Zimbra Collaboration through Improper Input Sanitization
CVE-2026-73570

8.9HIGH

Key Information:

Vendor

Zimbra

Vendor
CVE Published:
13 August 2026

What is CVE-2026-73570?

A remote code execution vulnerability affects Zimbra Collaboration Suite prior to version 10.1.20 when the zimbra-snmp package is active with SNMP notifications enabled. The vulnerability arises from improper sanitization of untrusted input during the SNMP notification processing. This flaw permits unauthenticated attackers to send specially crafted SMTP requests, which could lead to the execution of arbitrary operating system commands as the Zimbra user. This emphasizes the need for updated security measures to prevent unauthorized exploitation.

Affected Version(s)

Collaboration 0 < 10.1.20

References

CVSS V3.1

Score:
8.9
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.