CVE-2026-73575

LOW CVSS 3.1: 3.1 EPSS 0.11%
Updated Aug 21, 2026
Zimbra
Parameter Value
CVSS 3.1 (LOW)
Affected Versions before 10.1.17
Fixed In 10.1.17
Type CWE-352 (Cross-Site Request Forgery (CSRF))
Vendor Zimbra
Public PoC No

In Zimbra Collaboration (ZCS) before 10.1.17, a Cross-Site Request Forgery (CSRF) vulnerability exists in the Exchange Web Services (EWS) endpoint of Zimbra Collaboration (ZCS) due to insufficient validation of request content types. An attacker can exploit this vulnerability by causing an authenticated user to submit a crafted request, potentially allowing unauthorized actions to be performed on behalf of the victim.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
High
Difficult to exploit
Privileges Required
None
No privileges needed
User Interaction
Required
User action required

Impact Assessment

Confidentiality
None
No data leak
Integrity
Low
Partial data modification
Availability
None
No disruption

CVSS Vector v3.1

Vulnerable Products 1

Configuration From (including) Up to (excluding)
Zimbra Collaboration
cpe:2.3:a:zimbra:collaboration:*:*:*:*:*:*:*:*
10.1.17