Sceawere

Vulnerability Detail

CVE-2026-73570UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Zimbra Collaboration SNMP RCE Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8.9
Creation Date
5h ago
Vendor
Zimbra
Product
Collaboration
Attack Type
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L
Attack Complexity
HIGH

Narrative and Response

Description

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.9",
  "pubDate": "2026-08-13T16:19:06.003Z",
  "pubdate": "2026-08-13T16:19:06.003Z",
  "executiveSummary": "A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) prior to version 10.1.20, specifically when the optional zimbra-snmp package is installed and SNMP notifications are enabled.\nThis vulnerability arises from the improper sanitization of untrusted input during the processing of Simple Network Management Protocol (SNMP) notifications.\nAn unauthenticated, remote attacker can leverage this flaw by sending specially crafted Simple Mail Transfer Protocol (SMTP) requests to the target system.\nSuccessful exploitation allows the execution of arbitrary operating system commands with the privileges of the Zimbra user account.\nThe risk profile of this vulnerability is critical due to the lack of authentication required, the potential for complete system compromise within the context of the service user, and remote network exposure.\nRemediation requires updating Zimbra Collaboration to version 10.1.20 or later, or disabling the vulnerable zimbra-snmp package and associated SNMP notification features if immediate patching is not feasible.",
  "technicalDetails": "The vulnerability resides in the SNMP notification processing subsystem of Zimbra Collaboration (ZCS), specifically within components dependent on the optional zimbra-snmp package when SNMP notifications are actively enabled.\nThe root cause is identified as improper sanitization and validation of untrusted input received during the handling of internal messaging or notification states triggered via SMTP interactions.\nAttackers can initiate the attack flow by transmitting specially crafted SMTP requests to the exposed mail transfer agent services of the targeted Zimbra Collaboration server.\nThese malicious SMTP payloads are parsed and subsequently propagated or referenced within the SNMP notification processing workflow without adequate neutralization of shell metacharacters or command injection vectors.\nAs the system processes the tainted data stream during SNMP event generation or notification dispatch, the unsanitized input is passed to underlying operating system execution sinks.\nThis results in arbitrary command execution within the execution context and privilege level of the Zimbra service user.\nThe affected product is Zimbra Collaboration (ZCS) across versions prior to 10.1.20 where the zimbra-snmp package is installed and SNMP notifications are enabled.\nExploitation requires network access to the SMTP service ports exposed by the Zimbra server.\nNo prior authentication or user interaction is required for an attacker to deliver the malicious payload.\nPost-exploitation impact includes unauthorized execution of arbitrary system binaries and scripts, potential lateral movement, access to sensitive messaging data, and full compromise of the Zimbra service user environment."
}
CVE-2026-73570: Zimbra Collaboration SNMP RCE Vulnerability (HIGH Severity, CVSS: 8.9) - Sceawere