Sceawere

Vulnerability Detail

CVE-2026-73572UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Zimbra Stored XSS Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.1
Creation Date
5h ago
Vendor
Zimbra
Product
Collaboration
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

In Zimbra Collaboration (ZCS) before 10.1.17, a stored cross-site scripting (XSS) vulnerability exists in the Zimbra Classic Web Client due to insufficient sanitization of specific attachment content during inline preview. An attacker can send a crafted email containing a malicious attachment that, when previewed by a user, executes arbitrary JavaScript within the victim's browser session. Successful exploitation may allow an attacker to perform unauthorized actions on behalf of the victim user, potentially leading to data exfiltration or unauthorized access to sensitive information.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.1",
  "pubDate": "2026-08-13T16:19:06.287Z",
  "pubdate": "2026-08-13T16:19:06.287Z",
  "executiveSummary": "A stored cross-site scripting (XSS) vulnerability has been identified in Zimbra Collaboration (ZCS) prior to version 10.1.17, residing specifically within the Zimbra Classic Web Client.\nThe root vulnerability stems from insufficient sanitization of specific attachment content processed during inline preview operations.\nAn authenticated or unauthenticated attacker capable of delivering a crafted email to a target can leverage this flaw by embedding a malicious attachment designed to execute arbitrary JavaScript within the context of the victim's browser session upon previewing.\nSuccessful exploitation of this stored XSS allows attackers to execute unauthorized actions on behalf of the victim user, potentially resulting in sensitive data exfiltration, session hijacking, and unauthorized access to restricted mailbox information.\nThe risk implication is critical for collaborative environments where users routinely preview untrusted email attachments.\nMitigation requires updating the Zimbra Collaboration (ZCS) deployment to version 10.1.17 or later to ensure proper input sanitization and attachment handling.",
  "technicalDetails": "The vulnerability is classified as a stored cross-site scripting (XSS) flaw affecting the Zimbra Classic Web Client component of Zimbra Collaboration (ZCS) before version 10.1.17.\nThe root cause of the vulnerability lies in the improper neutralization of input within specific attachment content when the application renders an inline preview of the file.\nInstead of strictly encoding, sanitizing, or stripping potentially dangerous content, the application parses and renders the attachment payload directly within the Document Object Model (DOM) of the victim's browser session.\nThe attack vector involves sending an email containing a maliciously crafted attachment to a target user within or external to the organization.\nWhen the victim user interacts with the email interface to view the inline preview of the malicious attachment, the application processes the embedded payload.\nAs the browser interprets the unsanitized attachment content, the embedded malicious JavaScript executes in the security context of the victim's active session, inheriting the session cookies and Document privileges associated with the Zimbra Classic Web Client.\nNetwork exposure is inherent to any deployment accessible via standard mail protocols and web client interfaces.\nExploitation does not explicitly require privileged access prior to the attack, as external or internal entities can transmit the malicious email payload, although user interaction (previewing the attachment) is required to trigger execution.\nPost-exploitation capabilities include arbitrary script execution within the victim's session, enabling attackers to perform unauthorized state-changing actions, query internal APIs on behalf of the user, exfiltrate sensitive data, or compromise additional mailbox contents."
}
CVE-2026-73572: Zimbra Stored XSS Vulnerability (MEDIUM Severity, CVSS: 6.1) - Sceawere