Impact
An authorization bypass flaw in Zimbra Collaboration (ZCS) before version 10.1.17 allows an authenticated attacker to manipulate the SaveDraftRequest SOAP handler to send emails on behalf of arbitrary users. The vulnerability is classified as CWE-863, an implicit authorization bypass. By crafting specific SOAP requests, the attacker can impersonate another user without holding the requisite delegation or send-as permissions, enabling the delivery of messages that appear to originate from legitimate accounts.
Affected Systems
Zimbra Collaboration (ZCS) versions prior to 10.1.17 are affected. The flaw resides in the SaveDraftRequest SOAP handler and impacts any deployment of this product before the specified version.
Risk and Exploitability
The CVSS score of 3.1 indicates a low overall severity, and the EPSS score is not available. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires the attacker to be authenticated to the Zimbra SOAP interface and to have the ability to send SOAP requests, so it is not a public remote exploit but could be used by insiders or compromised accounts to send emails that appear to originate from other users.
OpenCVE Enrichment