Local File Inclusion in Zimbra Collaboration Web Client
CVE-2026-73574
3.1LOW
What is CVE-2026-73574?
A local file inclusion vulnerability was identified in the Zimbra Collaboration's Classic Web Client, prior to version 10.1.17. This issue arises from the inadequate validation of the 'fu' request parameter, permitting an attacker to craft paths that may lead to the unauthorized exposure of sensitive files, such as 'WEB-INF/web.xml', located within the web application directory. The risk is most evident in the Forward servlet, posing a significant threat to data security.
Affected Version(s)
Collaboration 0 < 10.1.17
