Sceawere

Vulnerability Detail

CVE-2026-73575UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Zimbra Collaboration EWS CSRF Vulnerability

Vulnerability Metadata

Severity
Low
Score / CVSS
3.1
Creation Date
5h ago
Vendor
Zimbra
Product
Collaboration
Attack Type
CWE-352 Cross-Site Request Forgery (CSRF)
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
Attack Complexity
HIGH

Narrative and Response

Description

In Zimbra Collaboration (ZCS) before 10.1.17, a Cross-Site Request Forgery (CSRF) vulnerability exists in the Exchange Web Services (EWS) endpoint of Zimbra Collaboration (ZCS) due to insufficient validation of request content types. An attacker can exploit this vulnerability by causing an authenticated user to submit a crafted request, potentially allowing unauthorized actions to be performed on behalf of the victim.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "3.1",
  "pubDate": "2026-08-13T16:19:06.767Z",
  "pubdate": "2026-08-13T16:19:06.767Z",
  "executiveSummary": "A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Exchange Web Services (EWS) endpoint of Zimbra Collaboration (ZCS) prior to version 10.1.17. This security flaw stems from insufficient validation of request content types by the application, allowing an attacker to bypass standard browser security controls for cross-origin state-changing operations.\nThe primary impact of this vulnerability is the potential execution of unauthorized actions on behalf of an authenticated victim. If successfully exploited, a malicious actor can leverage the victim's active session to interact with the EWS endpoint and trigger unintended operations within the Zimbra Collaboration environment.\nThe affected product is Zimbra Collaboration (ZCS) for all versions prior to 10.1.17. The risk implication is significant as it compromises the integrity of user sessions and enterprise collaboration data without requiring direct access to primary authentication credentials.\nTo achieve successful exploitation, the attacker must possess the capability to deliver a crafted malicious request to the victim, typically via social engineering vectors such as malicious links or compromised web pages. The exploitation requirement dictates that the target user must be authenticated to the Zimbra Collaboration instance during the attack execution, enabling the browser to automatically include session cookies with the forged request.",
  "technicalDetails": "The root cause of this vulnerability lies in the insufficient validation and enforcement of expected request content types within the Exchange Web Services (EWS) endpoint of Zimbra Collaboration (ZCS). Web applications that accept state-changing requests must rigorously validate that the incoming Content-Type header matches expected secure values, such as application/json or specific multipart formats, alongside utilizing anti-CSRF tokens.\nDue to the lack of strict content type validation, an attacker can construct a malicious cross-origin payload capable of submitting requests to the vulnerable EWS endpoint. When an authenticated user visits an attacker-controlled web page, the browser automatically appends session cookies to the target request. Because the EWS endpoint improperly validates the request content type, it processes the incoming payload as a legitimate command.\nThe vulnerable component is the Exchange Web Services (EWS) endpoint handling incoming API and protocol integration traffic within Zimbra Collaboration (ZCS). The affected versions include all deployments of Zimbra Collaboration (ZCS) prior to version 10.1.17.\nRegarding authentication and privilege requirements, the attack requires the victim to be actively authenticated to the Zimbra Collaboration platform with an established session. The network exposure is inherent to any deployment where the EWS endpoint is accessible to users over the network, allowing external web pages to initiate cross-origin requests.\nThe attack flow proceeds in a sequential manner. First, the attacker crafts a malicious web page or script designed to submit a forged request to the Zimbra Collaboration EWS endpoint. Second, the attacker entices an authenticated Zimbra user to load the malicious resource. Third, the victim's browser automatically includes valid session cookies while dispatching the crafted request to the server. Fourth, the vulnerable EWS endpoint processes the request due to inadequate content type validation. Finally, the unauthorized action is executed within the context of the victim's active session, leading to potential state modification or unauthorized data processing."
}
CVE-2026-73575: Zimbra Collaboration EWS CSRF Vulnerability (LOW Severity, CVSS: 3.1) - Sceawere