Description
An authorization bypass in the EWS FindItem handler of Zimbra Collaboration Suite 10.1.0 through 10.1.19 allows an authenticated user with EWS enabled to read complete mailbox items, including raw MIME and attachments, from arbitrary local accounts without a share or delegation grant.
Published: 2026-10-08
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized access to mailbox data
Action: Patch ASAP
AI Analysis

Impact

This vulnerability is an authorization bypass that occurs in the Extensible Web Services FindItem handler. An authenticated user with EWS enabled can construct a crafted composite folder or item identifier, allowing that user to read entire mailbox contents—including MIME text and attachments—from any local account. The effect is a serious breach of confidentiality, exposing private correspondence without a share or delegation grant (CWE‑639).

Affected Systems

The flaw exists in Zimbra Collaboration Suite versions 10.1.0 through 10.1.19. Users running any of those releases with EWS enabled are susceptible. Systems not on these releases or with EWS disabled are not affected.

Risk and Exploitability

With a CVSS score of 6.5, the risk is moderate. No EPSS value is available, and the vulnerability is not listed in the CISA KEV catalog, indicating no publicly known exploit at this time. The attacker must have valid EWS credentials, which could be obtained by compromise or social engineering. Once authenticated, the path is simple: issue a FindItem request with the crafted identifier to retrieve data from arbitrary mailboxes. The lack of required elevated privileges makes this a user‑level brute‑force of data, but still a significant threat in shared or multi‑tenant environments.

Generated by OpenCVE AI on October 8, 2026 at 17:48 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to the latest Zimbra Collaboration Suite release that removes the flaw, such as 10.1.20 or later.
  • If upgrading is not immediately possible, disable EWS for users who do not require it and limit EWS access to trusted IPs.
  • Apply least‑privilege policies by ensuring only authorized accounts have EWS enabled and monitor for abnormal FindItem usage patterns.

Generated by OpenCVE AI on October 8, 2026 at 17:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Zimbra
Zimbra zimbra Collaboration Suite
Vendors & Products Zimbra
Zimbra zimbra Collaboration Suite

Thu, 08 Oct 2026 16:45:00 +0000

Type Values Removed Values Added
Description An authorization bypass in the EWS FindItem handler of Zimbra Collaboration Suite 10.1.0 through 10.1.19 allows an authenticated user with EWS enabled to read complete mailbox items, including raw MIME and attachments, from arbitrary local accounts without a share or delegation grant.
Title Zimbra Collaboration Suite EWS Extension Authorization Bypass via Crafted Composite Folder/Item Identifier
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Zimbra Zimbra Collaboration Suite
cve-icon MITRE

Status: PUBLISHED

Assigner: rapid7

Published:

Updated: 2026-10-08T19:11:17.411Z

Reserved: 2026-06-02T14:57:14.369Z

Link: CVE-2026-10631

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-08T17:17:16.410

Modified: 2026-10-08T20:49:23.240

Link: CVE-2026-10631

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T18:45:17Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key