Sceawere

Vulnerability Detail

CVE-2026-73573UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Zimbra Briefcase Path Traversal

Vulnerability Metadata

Severity
Low
Score / CVSS
3.1
Creation Date
5h ago
Vendor
Zimbra
Product
Collaboration
Attack Type
CWE-24 Path Traversal: '../filedir'
Vector String
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
HIGH

Narrative and Response

Description

In Zimbra Collaboration (ZCS) before 10.1.17, a path traversal vulnerability exists in the Zimbra Briefcase document editing functionality due to improper validation of the packages parameter. An authenticated attacker can exploit this vulnerability by supplying a crafted path traversal sequence, potentially allowing unauthorized disclosure of sensitive files within the web application directory.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "3.1",
  "pubDate": "2026-08-13T16:19:06.437Z",
  "pubdate": "2026-08-13T16:19:06.437Z",
  "executiveSummary": "A path traversal vulnerability has been identified in Zimbra Collaboration (ZCS) prior to version 10.1.17, specifically residing within the Zimbra Briefcase document editing functionality. This security flaw stems from the improper input validation of the packages parameter supplied during file operations. An authenticated attacker can successfully exploit this vulnerability by transmitting a maliciously crafted path traversal sequence through the vulnerable endpoint. Successful exploitation of this flaw can lead to the unauthorized disclosure and reading of sensitive files located within the web application directory, thereby posing significant risks to confidentiality. The attack requires authentication within the target system, granting the attacker the capability to bypass intended directory restrictions and access arbitrary files accessible to the application context. Organizations utilizing affected versions of Zimbra Collaboration (ZCS) face potential information exposure risks if unauthorized users leverage this weakness. Remediation involves applying the vendor-supplied patch or upgrading the software to version 10.1.17 or later where input sanitization for the packages parameter is properly enforced.",
  "technicalDetails": "The vulnerability is classified as a path traversal flaw affecting the Zimbra Briefcase document editing component of Zimbra Collaboration (ZCS) prior to version 10.1.17. The root cause of the issue is the insufficient sanitization and improper validation of user-supplied input passed via the packages parameter. Because the application fails to adequately filter directory traversal sequences such as dot-dot-slash sequences, an authenticated attacker can manipulate the parameter to reference arbitrary file paths outside the intended working directory.\nThe exploitation method involves an attacker interacting with the Zimbra Briefcase document editing functionality and intercepting or crafting an HTTP request containing a maliciously constructed packages parameter. This parameter is injected with directory traversal patterns designed to navigate upward through the directory tree of the web application structure. Upon receiving the crafted payload, the vulnerable component processes the path without proper boundary enforcement, causing the underlying application to access and return the contents of files that should otherwise be restricted.\nRegarding authentication and privileges, exploitation requires the attacker to possess valid user credentials to access the Zimbra Collaboration (ZCS) environment and interact with the Briefcase feature. Network exposure includes access to the web application interface where the document editing functionality is hosted. The payload behavior centers on leveraging traversal sequences to read targeted files residing within the web application directory, resulting in post-exploitation impact characterized by the unauthorized disclosure of sensitive application data, configuration details, or other confidential files accessible under the web application server user context."
}
CVE-2026-73573: Zimbra Briefcase Path Traversal (LOW Severity, CVSS: 3.1) - Sceawere