Description
In Zimbra Collaboration (ZCS) before 10.1.17, a Cross-Site Request Forgery (CSRF) vulnerability exists in the Exchange Web Services (EWS) endpoint of Zimbra Collaboration (ZCS) due to insufficient validation of request content types. An attacker can exploit this vulnerability by causing an authenticated user to submit a crafted request, potentially allowing unauthorized actions to be performed on behalf of the victim.
Published: 2026-08-13
Score: 3.1 Low
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A Cross‑Site Request Forgery (CSRF) flaw exists in the Exchange Web Services endpoint of Zimbra Collaboration Service (ZCS) prior to version 10.1.17. The vulnerability stems from insufficient validation of request content types, which allows a malicious actor to entice an authenticated user into submitting a crafted request that the server processes as if it originated from that user. Successful exploitation could therefore lead to the unauthorized execution of privileged actions on the victim's behalf, such as altering account settings or performing other sensitive operations. This weakness aligns with CWE‑352, as it exploits the lack of proper origin verification.

Affected Systems

Products affected are Zimbra Collaboration Service installations running versions earlier than 10.1.17. All ZCS deployments that expose the EWS endpoint to authenticated web sessions are vulnerable, regardless of the hosting environment. The issue is not confined to a specific operating system or deployment type; any customer using ZCS before 10.1.17 is at risk.

Risk and Exploitability

The CVSS score of 3.1 indicates a low severity level, and the absence of an EPSS rating combined with the fact that the vulnerability is not listed in CISA's KEV catalog suggest a modest risk. Exploitation requires the victim to be logged in, to view a malicious page that forces a request to the vulnerable endpoint, and for the request to contain an accepted content type—conditions that limit spontaneous exploitation. While no public exploits are currently available, organizations running outdated ZCS should consider the risk moderate due to the potential impact on privileged user accounts and the relative ease of delivering forged requests via phishing or compromised web pages.

Generated by OpenCVE AI on August 13, 2026 at 17:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Zimbra Collaboration to version 10.1.17 or later to remove the vulnerability.
  • Restrict access to the Exchange Web Services (EWS) endpoint so that only trusted internal traffic can reach it, or block the endpoint entirely for external clients.
  • Deploy Web Application Firewall (WAF) or front‑end CSRF defenses that detect and block forged EWS requests, or ensure that client applications include anti‑CSRF tokens with those calls.

Generated by OpenCVE AI on August 13, 2026 at 17:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
Description In Zimbra Collaboration (ZCS) before 10.1.17, a Cross-Site Request Forgery (CSRF) vulnerability exists in the Exchange Web Services (EWS) endpoint of Zimbra Collaboration (ZCS) due to insufficient validation of request content types. An attacker can exploit this vulnerability by causing an authenticated user to submit a crafted request, potentially allowing unauthorized actions to be performed on behalf of the victim.
First Time appeared Zimbra
Zimbra collaboration
Weaknesses CWE-352
CPEs cpe:2.3:a:zimbra:collaboration:*:*:*:*:*:*:*:*
Vendors & Products Zimbra
Zimbra collaboration
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

Zimbra Collaboration
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-13T15:58:38.101Z

Reserved: 2026-08-12T22:00:05.774Z

Link: CVE-2026-73575

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-13T16:19:06.767

Modified: 2026-08-13T16:19:06.767

Link: CVE-2026-73575

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T17:30:06Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)