CVE-2026-50055
Received Received - Intake

Policy-enforcement Bypass in Zimbra Collaboration Suite via Sieve Notify

Vulnerability report for CVE-2026-50055, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: Rapid7, Inc.

Description

A policy-enforcement flaw in Zimbra Collaboration Suite allows an authenticated user to bypass disabled mail forwarding by using a Sieve notify action to send copies of email content and headers to an arbitrary address.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Zimbra Zimbra Collaboration Suite 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a policy-enforcement flaw in Zimbra Collaboration Suite. An authenticated user can bypass disabled mail forwarding by using a Sieve notify action to send email content and headers to an arbitrary address.

Impact Analysis

An attacker could exfiltrate sensitive email data even if mail forwarding is disabled, leading to potential data breaches or unauthorized access to confidential information.

Compliance Impact

This vulnerability could lead to unauthorized data disclosure, violating GDPR's data protection principles and HIPAA's confidentiality requirements, potentially resulting in legal penalties and loss of trust.

Mitigation Strategies

Disable Sieve notify actions in Zimbra Collaboration Suite to prevent unauthorized email forwarding. Review and update mail forwarding policies to ensure they cannot be bypassed. Monitor email logs for suspicious notify actions or external forwarding attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-50055. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart