Weak Cryptographic Key Generation in Zimbra Collaboration by Zimbra
CVE-2026-73576
6.3MEDIUM
What is CVE-2026-73576?
Zimbra Collaboration (ZCS) prior to version 10.1.17 contains a weakness in the cryptographic key generation process related to its OnlyOffice integration. The insecure random number generator used for creating the zimbraDocumentEditingJwtSecret results in insufficient entropy. An attacker who intercepts a JSON Web Token (JWT) signed with this secret could leverage offline brute-force techniques to uncover the signing secret, potentially leading to JWT forgery and further security implications.
Affected Version(s)
Collaboration 0 < 10.1.17
