Cross-Site Request Forgery in Zimbra Collaboration by Zimbra
CVE-2026-73575
3.1LOW
What is CVE-2026-73575?
A Cross-Site Request Forgery vulnerability has been identified in Zimbra Collaboration Suite (ZCS) versions prior to 10.1.17. This flaw exists within the Exchange Web Services (EWS) endpoint, primarily due to the lack of proper validation for request content types. If exploited, an attacker could entice an authenticated user into submitting a specially crafted request, which may allow unauthorized actions to be executed on behalf of the user, potentially compromising sensitive data and operations.
Affected Version(s)
Collaboration 0 < 10.1.17
