Description
In Zimbra Collaboration (ZCS) before 10.1.17, a stored cross-site scripting (XSS) vulnerability exists in the Zimbra Classic Web Client due to insufficient sanitization of specific attachment content during inline preview. An attacker can send a crafted email containing a malicious attachment that, when previewed by a user, executes arbitrary JavaScript within the victim's browser session. Successful exploitation may allow an attacker to perform unauthorized actions on behalf of the victim user, potentially leading to data exfiltration or unauthorized access to sensitive information.
Published: 2026-08-13
Score: 6.1 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a stored XSS in the Zimbra Classic Web Client. When a user previews an attachment that contains specially crafted content, the browser executes arbitrary JavaScript in the context of the victim’s session. This allows the attacker to perform unauthorized actions on behalf of the victim, such as altering data, exfiltrating sensitive information, or executing further malicious code. The weakness is a classic cross‑site scripting flaw (CWE‑79).

Affected Systems

Zimbra Collaboration Suite (ZCS) versions prior to 10.1.17 are vulnerable. Any system that hosts or serves Zimbra Classic Web Client and accepts user‑supplied email attachments is at risk. No specific product sub‑versions are listed beyond the major release.

Risk and Exploitability

The CVSS base score of 6.1 indicates a medium severity. The EPSS score is not available, so the current likelihood of exploitation is uncertain, but the vulnerability is not yet catalogued in the CISA KEV list. The most probable attack vector is remote delivery of a malicious email containing an attachment that a victim views in their browser. If the inline preview feature is enabled, the attacker can trigger the payload simply by having the victim preview the attachment, without the need for additional user interaction beyond opening the message.

Generated by OpenCVE AI on August 13, 2026 at 16:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Zimbra Collaboration Suite to version 10.1.17 or later.
  • Disable inline preview of attachments in the web client to prevent execution of embedded scripts.
  • Monitor email traffic for suspicious attachments and educate users about potential XSS risks.

Generated by OpenCVE AI on August 13, 2026 at 16:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Title Stored XSS with Inline Attachment Preview in Zimbra Classic Web Client

Thu, 13 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
Description In Zimbra Collaboration (ZCS) before 10.1.17, a stored cross-site scripting (XSS) vulnerability exists in the Zimbra Classic Web Client due to insufficient sanitization of specific attachment content during inline preview. An attacker can send a crafted email containing a malicious attachment that, when previewed by a user, executes arbitrary JavaScript within the victim's browser session. Successful exploitation may allow an attacker to perform unauthorized actions on behalf of the victim user, potentially leading to data exfiltration or unauthorized access to sensitive information.
First Time appeared Zimbra
Zimbra collaboration
Weaknesses CWE-79
CPEs cpe:2.3:a:zimbra:collaboration:*:*:*:*:*:*:*:*
Vendors & Products Zimbra
Zimbra collaboration
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Zimbra Collaboration
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-13T15:57:54.098Z

Reserved: 2026-08-12T21:51:54.435Z

Link: CVE-2026-73572

cve-icon Vulnrichment

Updated: 2026-08-13T15:57:49.092Z

cve-icon NVD

Status : Received

Published: 2026-08-13T16:19:06.287

Modified: 2026-08-13T16:19:06.287

Link: CVE-2026-73572

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T18:15:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')