Weak Cryptographic Key Generation in Zimbra Collaboration by Zimbra
CVE-2026-73576

6.3MEDIUM

Key Information:

Vendor

Zimbra

Vendor
CVE Published:
13 August 2026

What is CVE-2026-73576?

Zimbra Collaboration (ZCS) prior to version 10.1.17 contains a weakness in the cryptographic key generation process related to its OnlyOffice integration. The insecure random number generator used for creating the zimbraDocumentEditingJwtSecret results in insufficient entropy. An attacker who intercepts a JSON Web Token (JWT) signed with this secret could leverage offline brute-force techniques to uncover the signing secret, potentially leading to JWT forgery and further security implications.

Affected Version(s)

Collaboration 0 < 10.1.17

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.