Impact
An authorization flaw in the GrantRightsRequest SOAP handler allows any authenticated user to grant another local account the loginAs delegation right. This permission grants persistent mailbox access and the ability to send mail on behalf of the grantee, even after passwords are changed or sessions expire. The vulnerability is a direct privilege escalation, exposing sensitive email content and potentially facilitating spam or phishing campaigns.
Affected Systems
The vulnerability affects Zimbra Collaboration Suite, but specific product versions are not disclosed in the advisory. All installations of the suite that have not applied the latest security update for the grant rights functionality may be vulnerable.
Risk and Exploitability
The CVSS score is 7.1, indicating a high severity impact. No EPSS score is available, and the flaw is not listed in the CISA KEV catalog, so widespread exploitation has not been documented. The likely attack vector is via authenticated SOAP requests from any user inside the Zimbra environment, making the flaw exploitable both on internal and potentially on external network interfaces if the SOAP endpoint is exposed.
OpenCVE Enrichment