Description
In Zimbra Collaboration (ZCS) before 10.1.17, a path traversal vulnerability exists in the Zimbra Briefcase document editing functionality due to improper validation of the packages parameter. An authenticated attacker can exploit this vulnerability by supplying a crafted path traversal sequence, potentially allowing unauthorized disclosure of sensitive files within the web application directory.
Published: 2026-08-13
Score: 3.1 Low
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a path traversal flaw in the Zimbra Briefcase document editing feature caused by improper validation of the packages parameter. An authenticated user can craft a traversal sequence, gaining read access to files outside the intended container. The weakness is classified as CWE‑24 (Improper Restriction of Operations within the File System). The impact is limited to unauthorized file disclosure rather than arbitrary code execution or denial of service, reflected in the CVSS score of 3.1.

Affected Systems

The affected product is the Zimbra Collaboration Server (ZCS). Versions prior to 10.1.17 contain the flaw; later releases contain the fix. No specific sub‑versions are listed beyond this cutoff.

Risk and Exploitability

Given the CVSS of 3.1, the overall severity is low. No EPSS data is available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting a modest threat level. However, because the attack requires authentication and targets privileged users, internal actors or compromised accounts could leverage it to exfiltrate confidential data. The risk remains mitigated by applying the available update, with residual risk if the patch cannot be deployed promptly.

Generated by OpenCVE AI on August 13, 2026 at 16:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Zimbra Collaboration to version 10.1.17 or later to apply the vendor‑supplied fix for the path traversal flaw.
  • If an upgrade is not immediately feasible, restrict Briefcase access to trusted users only or disable the Briefcase feature to eliminate the attack surface.
  • Revoke or reduce privileges for accounts that have no legitimate need to edit or manage Briefcase documents, thereby limiting the possible exploitation scope.

Generated by OpenCVE AI on August 13, 2026 at 16:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Title Zimbra Briefcase Path Traversal Vulnerability Allowing Sensitive File Disclosure

Thu, 13 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
Description In Zimbra Collaboration (ZCS) before 10.1.17, a path traversal vulnerability exists in the Zimbra Briefcase document editing functionality due to improper validation of the packages parameter. An authenticated attacker can exploit this vulnerability by supplying a crafted path traversal sequence, potentially allowing unauthorized disclosure of sensitive files within the web application directory.
First Time appeared Zimbra
Zimbra collaboration
Weaknesses CWE-24
CPEs cpe:2.3:a:zimbra:collaboration:*:*:*:*:*:*:*:*
Vendors & Products Zimbra
Zimbra collaboration
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Zimbra Collaboration
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-13T15:58:09.171Z

Reserved: 2026-08-12T21:54:20.822Z

Link: CVE-2026-73573

cve-icon Vulnrichment

Updated: 2026-08-13T15:58:03.541Z

cve-icon NVD

Status : Received

Published: 2026-08-13T16:19:06.437

Modified: 2026-08-13T16:19:06.437

Link: CVE-2026-73573

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T18:45:04Z

Weaknesses
  • CWE-24

    Path Traversal: '../filedir'