CVE-2026-73574
Received Received - Intake

Local File Inclusion in Zimbra Collaboration

Vulnerability report for CVE-2026-73574, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-13

Last updated on: 2026-08-13

Assigner: MITRE

Description

In Zimbra Collaboration before 10.1.17, a local file inclusion (LFI) vulnerability exists in the Zimbra Classic Web Client due to improper validation of the fu request parameter. An unauthenticated attacker can exploit this vulnerability by supplying a crafted path, potentially allowing unauthorized disclosure of protected files, such as WEB-INF/web.xml, within the web application directory. This occurs in the Forward servlet.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-13
Last Modified
2026-08-13
Generated
2026-08-13
AI Q&A
2026-08-13
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
zimbra zimbra_collaboration to 10.1.17 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-669 The product does not properly transfer a resource/behavior to another sphere, or improperly imports a resource/behavior from another sphere, in a manner that provides unintended control over that resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a local file inclusion (LFI) vulnerability in Zimbra Collaboration before version 10.1.17. It exists in the Zimbra Classic Web Client due to improper validation of the fu request parameter in the Forward servlet. An unauthenticated attacker can exploit this by providing a specially crafted path to access protected files like WEB-INF/web.xml within the web application directory.

Detection Guidance

To detect this vulnerability, inspect network traffic for suspicious requests to the Forward servlet with crafted fu parameters. Check logs for unusual file access patterns, especially targeting WEB-INF/web.xml or other protected files. No specific commands are provided in the context.

Impact Analysis

An attacker could exploit this to read sensitive files on the server, potentially exposing configuration details or other protected data. This may lead to further attacks if credentials or other sensitive information are disclosed.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, which may violate compliance requirements such as GDPR or HIPAA. Exposure of protected files could result in data breaches, triggering regulatory penalties and legal consequences.

Mitigation Strategies

Upgrade Zimbra Collaboration to version 10.1.17 or later to address the LFI vulnerability in the Forward servlet.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-73574. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart