CVE-2026-73576

MEDIUM CVSS 3.1: 6.3 EPSS 0.19%
Updated Aug 21, 2026
Zimbra
Parameter Value
CVSS 6.3 (MEDIUM)
Affected Versions before 10.1.17
Fixed In 10.1.17
Type CWE-1241
Vendor Zimbra
Public PoC No

In Zimbra Collaboration (ZCS) before 10.1.17, weak cryptographic key generation vulnerability exists in the OnlyOffice integration. The zimbraDocumentEditingJwtSecret is generated using an insecure random number generator, resulting in insufficient entropy. An attacker who obtains a JWT signed with the generated secret may be able to recover the JWT signing secret through offline brute-force, potentially enabling JWT forgery.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
High
Difficult to exploit
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
None
No data leak
Integrity
High
Complete data modification
Availability
None
No disruption

CVSS Vector v3.1

Weakness Type (CWE)

Vulnerable Products 1

Configuration From (including) Up to (excluding)
Zimbra Collaboration
cpe:2.3:a:zimbra:collaboration:*:*:*:*:*:*:*:*
10.1.17