Description
An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Modern recipient clicks Accept Share, allowing the attacker to access mailbox data and act as the victim.
Published: 2026-09-25
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: Browser‑based Remote Code Execution via stored XSS
Action: Patch Now
AI Analysis

Impact

An unauthenticated attacker can forge a share invitation that, when clicked by a logged‑in recipient, executes stored cross‑site scripting within the Zimbra Modern Web Client. This script runs with the victim’s browser privileges, enabling the attacker to read mailbox contents and perform actions as the legitimate user, effectively creating a session hijack. The weakness is a classic stored XSS (CWE‑79) that grants full read/write access to the victim’s mailbox data.

Affected Systems

The vulnerability affects the Zimbra Collaboration Suite (ZCS) Modern Web Client in all deployed versions, as no specific product version range was identified in the advisory. Any installation that serves the modern web interface is potentially impacted.

Risk and Exploitability

The CVSS score of 9.3 indicates a high‑severity risk. Attackers need only to deliver a forged link to a user who has recently logged into Zimbra; no prior authentication is required. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, but the high impact score and plausible attack vector suggest that exploitation is likely if no mitigations are applied.

Generated by OpenCVE AI on September 25, 2026 at 17:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official security patch for Zimbra Collaboration Suite as soon as it becomes available from Zimbra.
  • If a patch is not yet released, temporarily disable or restrict the share acceptance feature in the Modern Web Client until a fix can be applied.
  • Implement web‑application firewall rules or browser security settings that block the execution of scripts injected via share notification links.

Generated by OpenCVE AI on September 25, 2026 at 17:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 25 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
Description An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Modern recipient clicks Accept Share, allowing the attacker to access mailbox data and act as the victim.
Title Zimbra Collaboration Suite Modern Web Client Stored Cross-Site Scripting via Forged Share Invitation
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: rapid7

Published:

Updated: 2026-09-25T16:11:07.666Z

Reserved: 2026-09-18T12:22:38.559Z

Link: CVE-2026-93642

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-25T14:17:23.423

Modified: 2026-09-25T17:17:19.750

Link: CVE-2026-93642

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-25T17:15:15Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')