Description
An authorization flaw in Zimbra Collaboration Suite’s GrantRightsRequest allows an attacker with access to an authenticated account to grant another local account the loginAs right, creating persistent mailbox access and mail-sending authority that survives password changes and session expiry.
Published: 2026-10-08
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Privilege Escalation – Unauthorized mailbox access
Action: Apply Patch
AI Analysis

Impact

An authorization flaw in the GrantRightsRequest SOAP handler allows any authenticated user to grant another local account the loginAs delegation right. This permission grants persistent mailbox access and the ability to send mail on behalf of the grantee, even after passwords are changed or sessions expire. The vulnerability is a direct privilege escalation, exposing sensitive email content and potentially facilitating spam or phishing campaigns.

Affected Systems

The vulnerability affects Zimbra Collaboration Suite, but specific product versions are not disclosed in the advisory. All installations of the suite that have not applied the latest security update for the grant rights functionality may be vulnerable.

Risk and Exploitability

The CVSS score is 7.1, indicating a high severity impact. No EPSS score is available, and the flaw is not listed in the CISA KEV catalog, so widespread exploitation has not been documented. The likely attack vector is via authenticated SOAP requests from any user inside the Zimbra environment, making the flaw exploitable both on internal and potentially on external network interfaces if the SOAP endpoint is exposed.

Generated by OpenCVE AI on October 8, 2026 at 17:48 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest patch or upgrade to a Zimbra Collaboration Suite version that corrects the GrantRightsRequest authorization flaw.
  • Restrict the loginAs delegation privilege to a minimal set of trusted accounts and perform regular reviews of delegated rights.
  • Monitor SOAP logs for GrantRightsRequest activity and audit account permissions, revoking any unauthorized delegations as needed.
  • Consider disabling the GrantRightsRequest SOAP handler or the loginAs feature temporarily, if the configuration allows, until a patch can be applied.

Generated by OpenCVE AI on October 8, 2026 at 17:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Zimbra
Zimbra zimbra Collaboration Suite
Vendors & Products Zimbra
Zimbra zimbra Collaboration Suite

Thu, 08 Oct 2026 16:45:00 +0000

Type Values Removed Values Added
Description An authorization flaw in Zimbra Collaboration Suite’s GrantRightsRequest allows an attacker with access to an authenticated account to grant another local account the loginAs right, creating persistent mailbox access and mail-sending authority that survives password changes and session expiry.
Title Zimbra Collaboration Suite GrantRightsRequest SOAP Handler Allows Self-Granting of Undocumented loginAs Mailbox Delegation Right
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Zimbra Zimbra Collaboration Suite
cve-icon MITRE

Status: PUBLISHED

Assigner: rapid7

Published:

Updated: 2026-10-08T19:10:47.375Z

Reserved: 2026-06-03T09:35:31.591Z

Link: CVE-2026-50054

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-08T17:17:17.180

Modified: 2026-10-08T20:49:23.240

Link: CVE-2026-50054

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T18:30:07Z

Weaknesses
  • CWE-269

    Improper Privilege Management