Impact
This vulnerability is an authorization bypass that occurs in the Extensible Web Services FindItem handler. An authenticated user with EWS enabled can construct a crafted composite folder or item identifier, allowing that user to read entire mailbox contents—including MIME text and attachments—from any local account. The effect is a serious breach of confidentiality, exposing private correspondence without a share or delegation grant (CWE‑639).
Affected Systems
The flaw exists in Zimbra Collaboration Suite versions 10.1.0 through 10.1.19. Users running any of those releases with EWS enabled are susceptible. Systems not on these releases or with EWS disabled are not affected.
Risk and Exploitability
With a CVSS score of 6.5, the risk is moderate. No EPSS value is available, and the vulnerability is not listed in the CISA KEV catalog, indicating no publicly known exploit at this time. The attacker must have valid EWS credentials, which could be obtained by compromise or social engineering. Once authenticated, the path is simple: issue a FindItem request with the crafted identifier to retrieve data from arbitrary mailboxes. The lack of required elevated privileges makes this a user‑level brute‑force of data, but still a significant threat in shared or multi‑tenant environments.
OpenCVE Enrichment