CVE-2026-93641
9.3Zimbra · Collaboration Suite (ZCS)
An unauthenticated sender can trigger stored XSS in Zimbra Collaboration Suite (ZCS) via a forged share notification, leading to unauthorized access to recipient mailbox data.
Executive summary
A critical stored Cross-Site Scripting vulnerability in Zimbra Collaboration Suite (ZCS) allows unauthenticated attackers to compromise mailbox data and impersonate users.
Vulnerability
This vulnerability is a stored cross-site scripting (CWE-79) flaw triggered when a user clicks a malicious share notification. The attack originates from an unauthenticated sender and allows the execution of arbitrary scripts within the context of the authenticated recipient.
Business impact
The ability for an attacker to access mailbox data and act as the victim represents a severe risk to organizational confidentiality and integrity. Given the CVSS score of 9.3, this vulnerability is classified as critical because it facilitates full account takeover and potential lateral movement within the email environment.
Remediation
Immediate Action: Upgrade Zimbra Collaboration Suite (ZCS) to version 10.1.21 or later immediately to apply the vendor-provided patch.
Proactive Monitoring: Monitor mailbox access logs for unusual login patterns or unauthorized delegation requests that may indicate an account compromise.
Compensating Controls: Implement strict Content Security Policy (CSP) headers and utilize a Web Application Firewall (WAF) to filter malicious scripts in incoming email notifications.
Exploitation status
Public Exploit Available: No
Analyst recommendation
This vulnerability presents a severe risk to the security of all Zimbra users due to the potential for complete account takeover. Organizations must prioritize the deployment of the 10.1.21 update across all affected ZCS instances to eliminate this attack vector. Failure to patch may result in unauthorized disclosure of sensitive communications and potential business email compromise.
More Zimbra CVEs
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief critical section
Sources
Originally found and disclosed by Jonah Burgess (CryptoCat), Senior Security Researcher, Rapid7, per the CVE Program record.