Description
An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Classic recipient clicks Accept Share, allowing the attacker to access mailbox data and act as the victim.
Published: 2026-09-25
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: Stored Cross‑Site Scripting that enables an attacker to run malicious scripts in a victim’s browser, potentially exposing mailbox content and acting on the victim’s behalf
Action: Patch Today
AI Analysis

Impact

An unauthenticated sender can forge a share notification that embeds malicious script code. When a signed‑in user clicks “Accept Share”, the Classic Web Client stores and executes the script, allowing the attacker to read mailbox data and impersonate the user. The vulnerability is a classic stored XSS flaw (CWE‑79) that can lead to data theft and credential compromise.

Affected Systems

The flaw impacts all installations of the Zimbra Collaboration Suite Classic Web Client that enable the share invitation feature. No specific software version ranges are listed, so every deployed instance is potentially vulnerable until a vendor release containing the fix is applied.

Risk and Exploitability

The CVSS score is 9.3, reflecting a high‑severity compromise vector. EPSS data is unavailable and the vulnerability is not listed in CISA’s KEV catalog, suggesting no publicly documented exploit yet. Attackers do not need to authenticate and only require that a victim opens the forged share link, which is likely to happen if users are not cautious. The risk is therefore significant for any organization using Zimbra Classic without the latest security update.

Generated by OpenCVE AI on September 25, 2026 at 17:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Zimbra Collaboration Suite update that addresses the forged share invitation XSS flaw.
  • Disable or restrict the ability for unauthenticated users to send share invitations through the Zimbra admin console or configuration settings.
  • Implement a Content Security Policy and enable XSS filtering in the Classic Web Client to block malicious script execution.
  • Regularly audit mailbox accounts for unexpected share invitations and educate users about the risks of clicking unfamiliar links.

Generated by OpenCVE AI on September 25, 2026 at 17:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 25 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Classic recipient clicks Accept Share, allowing the attacker to access mailbox data and act as the victim.
Title Zimbra Collaboration Suite Classic Web Client Stored Cross-Site Scripting via Forged Share Invitation
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: rapid7

Published:

Updated: 2026-09-25T16:11:43.921Z

Reserved: 2026-09-18T12:22:38.559Z

Link: CVE-2026-93641

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-25T14:17:23.290

Modified: 2026-09-25T17:17:19.650

Link: CVE-2026-93641

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-25T17:30:16Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')