Cross-Site Request Forgery in Zimbra Collaboration by Zimbra
CVE-2026-73575

3.1LOW

Key Information:

Vendor

Zimbra

Vendor
CVE Published:
13 August 2026

What is CVE-2026-73575?

A Cross-Site Request Forgery vulnerability has been identified in Zimbra Collaboration Suite (ZCS) versions prior to 10.1.17. This flaw exists within the Exchange Web Services (EWS) endpoint, primarily due to the lack of proper validation for request content types. If exploited, an attacker could entice an authenticated user into submitting a specially crafted request, which may allow unauthorized actions to be executed on behalf of the user, potentially compromising sensitive data and operations.

Affected Version(s)

Collaboration 0 < 10.1.17

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.