Local File Inclusion in Zimbra Collaboration Web Client
CVE-2026-73574

3.1LOW

Key Information:

Vendor

Zimbra

Vendor
CVE Published:
13 August 2026

What is CVE-2026-73574?

A local file inclusion vulnerability was identified in the Zimbra Collaboration's Classic Web Client, prior to version 10.1.17. This issue arises from the inadequate validation of the 'fu' request parameter, permitting an attacker to craft paths that may lead to the unauthorized exposure of sensitive files, such as 'WEB-INF/web.xml', located within the web application directory. The risk is most evident in the Forward servlet, posing a significant threat to data security.

Affected Version(s)

Collaboration 0 < 10.1.17

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.