Path Traversal Vulnerability in Zimbra Collaboration
CVE-2026-73573

3.1LOW

Key Information:

Vendor

Zimbra

Vendor
CVE Published:
13 August 2026

What is CVE-2026-73573?

A vulnerability exists in Zimbra Collaboration (ZCS) versions before 10.1.17, specifically within the document editing functionality of Zimbra Briefcase. This flaw arises from insufficient validation of input, particularly in the packages parameter, allowing an authenticated attacker to exploit this vulnerability by crafting a malicious path traversal sequence. Successful exploitation can lead to unauthorized access and disclosure of sensitive files within the web application directory, posing significant security risks.

Affected Version(s)

Collaboration 0 < 10.1.17

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.