CVE-2026-73572
Received Received - Intake

Stored XSS in Zimbra Collaboration Classic Web Client

Vulnerability report for CVE-2026-73572, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-13

Last updated on: 2026-08-13

Assigner: MITRE

Description

In Zimbra Collaboration (ZCS) before 10.1.17, a stored cross-site scripting (XSS) vulnerability exists in the Zimbra Classic Web Client due to insufficient sanitization of specific attachment content during inline preview. An attacker can send a crafted email containing a malicious attachment that, when previewed by a user, executes arbitrary JavaScript within the victim's browser session. Successful exploitation may allow an attacker to perform unauthorized actions on behalf of the victim user, potentially leading to data exfiltration or unauthorized access to sensitive information.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-13
Last Modified
2026-08-13
Generated
2026-08-13
AI Q&A
2026-08-13
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
zimbra zimbra_collaboration to 10.1.17 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a stored cross-site scripting (XSS) vulnerability in Zimbra Collaboration (ZCS) before version 10.1.17. It occurs because attachment content is not properly sanitized during inline preview in the Zimbra Classic Web Client. An attacker can send a malicious email with a crafted attachment that executes arbitrary JavaScript when previewed by a user. This allows the attacker to perform unauthorized actions on behalf of the victim, potentially leading to data theft or unauthorized access.

Detection Guidance

Detecting this vulnerability requires monitoring for suspicious attachments in Zimbra emails. Check for emails with attachments that trigger inline preview in the Classic Web Client. Inspect attachment filenames and content types for unusual patterns. Enable server-side logging for attachment processing in Zimbra logs to identify potential exploitation attempts.

Impact Analysis

If you use Zimbra Collaboration before version 10.1.17, an attacker could trick you into previewing a malicious attachment in your email. This could allow the attacker to steal sensitive data, such as login credentials or personal information, or perform actions on your behalf without your consent. The impact includes potential data breaches, unauthorized access to accounts, and loss of confidentiality.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR and HIPAA by enabling unauthorized access to personal or protected health information. GDPR requires protecting personal data, and HIPAA mandates safeguarding health information. A successful exploit could result in data breaches, leading to legal penalties, fines, and reputational damage for organizations failing to meet these regulatory requirements.

Mitigation Strategies

Upgrade Zimbra Collaboration to version 10.1.17 or later immediately. Disable inline preview for attachments in the Classic Web Client until patched. Implement email attachment scanning with XSS detection rules. Monitor network traffic for unusual JavaScript execution patterns from email clients.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-73572. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart