Description
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.
Published: 2026-08-13
Score: 8.9 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is a command‑injection weakness that allows an unauthenticated attacker to send crafted SMTP requests through SNMP notifications, causing the Zimbra server to execute arbitrary operating‑system commands as the Zimbra user. This can give the attacker full control of the affected system. The underlying weakness is command injection (CWE‑78).

Affected Systems

Zimbra Collaboration (ZCS) versions earlier than 10.1.20 are impacted, but only when the optional zimbra‑snmp package is installed and SNMP notifications are enabled. The vulnerability exists in the notification processing code that handles untrusted SNMP input.

Risk and Exploitability

The CVSS score of 8.9 indicates a high severity. No EPSS score is reported, and the vulnerability is not currently listed in the CISA KEV catalog, but the lack of authentication and remote access via SNMP mean that the attack can be launched from a network accessible to the attacker. The combination of high severity, a remote attack vector, and the ability to execute arbitrary code makes the risk significant and warrants urgent action.

Generated by OpenCVE AI on August 13, 2026 at 16:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Zimbra update that remediates this flaw (at least version 10.1.20).
  • If immediate patching is not possible, uninstall the zimbra‑snmp package and disable SNMP notifications to eliminate the attack surface.
  • Configure SNMP to be accessible only from trusted hosts, or segment the network so that the SNMP service is not exposed to potential attackers.

Generated by OpenCVE AI on August 13, 2026 at 16:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via SNMP Notification in Zimbra Collaboration Before 10.1.20

Thu, 13 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
Description A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.
First Time appeared Zimbra
Zimbra collaboration
Weaknesses CWE-78
CPEs cpe:2.3:a:zimbra:collaboration:*:*:*:*:*:*:*:*
Vendors & Products Zimbra
Zimbra collaboration
References
Metrics cvssV3_1

{'score': 8.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L'}


Subscriptions

Zimbra Collaboration
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-13T15:57:25.921Z

Reserved: 2026-08-12T21:44:20.945Z

Link: CVE-2026-73570

cve-icon Vulnrichment

Updated: 2026-08-13T15:57:21.280Z

cve-icon NVD

Status : Received

Published: 2026-08-13T16:19:06.003

Modified: 2026-08-13T16:19:06.003

Link: CVE-2026-73570

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T16:30:03Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')