Ad

CVE-2026-33371

MEDIUM CVSS 3.1: 4.3 EPSS 0.05%
Updated Mar 24, 2026
Zimbra
Parameter Value
CVSS 4.3 (MEDIUM)
Type CWE-611
Vendor Zimbra
Public PoC No

An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. An XML External Entity (XXE) vulnerability exists in the Zimbra Exchange Web Services (EWS) SOAP interface due to improper handling of XML input. An authenticated attacker can submit crafted XML data that is processed by an XML parser with external entity resolution enabled.

Successful exploitation may allow disclosure of sensitive local files from the server.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
Low
Partial data leak
Integrity
None
No data modification
Availability
None
No disruption

CVSS Vector v3.1

Weakness Type (CWE)