Impact
A policy‑enforcement flaw in the Zimbra Collaboration Suite permits an authenticated user to circumvent disabled mail forwarding by exploiting the Sieve "notify" action. When a user creates a Sieve script that includes variable expansion, the email content and headers can be sent to an arbitrary address, enabling the exfiltration of sensitive information. The weakness is a classic example of an authorization bypass that compromises data confidentiality through an otherwise restricted functionality.
Affected Systems
The vulnerability affects the Zimbra Collaboration Suite. No specific affected versions are listed in the CVE data; administrators should verify whether their deployed Zimbra installation contains the flaw and apply any available vendor updates accordingly.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. Because the flaw requires the attacker to be an authenticated user with Sieve script creation privileges, it is not exploitable by an unauthenticated attacker, but it provides a viable path for a legitimate user to leak mailbox content. The EPSS score is not available and the vulnerability is not listed in CISA KEV, suggesting that widespread exploitation is not yet observed. Nevertheless, any compromised Zimbra account could use this mechanism to send copies of private emails to unauthorized recipients, representing a significant confidentiality risk.
OpenCVE Enrichment