No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 13 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Impersonation via Bypassed Delegated Email Sending in Zimbra Collaboration |
Thu, 13 Aug 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Impersonation via Bypassed Delegated Email Sending in Zimbra Collaboration |
Thu, 13 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 13 Aug 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authorization bypass vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.17 due to improper authorization validation in delegated email sending functionality. An authenticated attacker can send specially crafted SOAP requests to impersonate another user and send emails without possessing the required delegation or send-as permissions. This occurs in theĀ SaveDraftRequest SOAP handler. | An authorization bypass vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.17 due to improper authorization validation in delegated email sending functionality. An authenticated attacker can send specially crafted SOAP requests to impersonate another user and send emails without possessing the required delegation or send-as permissions. This occurs in the SaveDraftRequest SOAP handler. |
Thu, 13 Aug 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authorization bypass vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.17 due to improper authorization validation in delegated email sending functionality. An authenticated attacker can send specially crafted SOAP requests to impersonate another user and send emails without possessing the required delegation or send-as permissions. This occurs in theĀ SaveDraftRequest SOAP handler. | |
| First Time appeared |
Zimbra
Zimbra collaboration |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:zimbra:collaboration:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Zimbra
Zimbra collaboration |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-08-13T15:57:39.948Z
Reserved: 2026-08-12T21:49:11.961Z
Link: CVE-2026-73571
Updated: 2026-08-13T15:57:34.898Z
Status : Received
Published: 2026-08-13T16:19:06.150
Modified: 2026-08-13T16:19:06.150
Link: CVE-2026-73571
No data.
OpenCVE Enrichment
Updated: 2026-08-13T18:15:04Z