CVE-2026-73576
Received Received - Intake

Weak Cryptographic Key Generation in Zimbra Collaboration OnlyOffice Integration

Vulnerability report for CVE-2026-73576, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-13

Last updated on: 2026-08-13

Assigner: MITRE

Description

In Zimbra Collaboration (ZCS) before 10.1.17,Β weak cryptographic key generation vulnerability exists in the OnlyOffice integration. The zimbraDocumentEditingJwtSecret is generated using an insecure random number generator, resulting in insufficient entropy. An attacker who obtains a JWT signed with the generated secret may be able to recover the JWT signing secret through offline brute-force, potentially enabling JWT forgery.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-13
Last Modified
2026-08-13
Generated
2026-08-13
AI Q&A
2026-08-13
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
zimbra zimbra_collaboration to 10.1.17 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1241 The device uses an algorithm that is predictable and generates a pseudo-random number.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in Zimbra Collaboration before version 10.1.17. It involves weak cryptographic key generation for the OnlyOffice integration. The JWT secret used for document editing is created with an insecure random number generator, leading to low entropy. This allows attackers to potentially recover the secret through brute-force attacks and forge JWTs.

Impact Analysis

If exploited, an attacker could forge JWTs to gain unauthorized access to document editing features. This may allow them to manipulate or steal sensitive documents processed through the OnlyOffice integration in Zimbra.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating confidentiality requirements in GDPR and HIPAA. Organizations using affected Zimbra versions may face compliance violations due to insufficient cryptographic protections.

Mitigation Strategies

Upgrade Zimbra Collaboration Suite (ZCS) to version 10.1.17 or later to address the weak cryptographic key generation issue in OnlyOffice integration.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-73576. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart