Authorization Bypass in Zimbra Collaboration
CVE-2026-73571
3.1LOW
What is CVE-2026-73571?
An authorization bypass vulnerability in Zimbra Collaboration Suite (ZCS) prior to version 10.1.17 can allow authenticated attackers to send deceptive emails by exploiting the delegated email sending feature. This vulnerability is triggered when attackers send specially crafted SOAP requests, thereby circumventing necessary validation checks. Consequently, attackers can impersonate other users without proper permissions, posing significant risks to organizational email integrity and security.
Affected Version(s)
Collaboration 0 < 10.1.17
