CVE-2026-93642

9.3

Zimbra · Collaboration Suite (ZCS)

A stored cross-site scripting vulnerability in Zimbra Collaboration Suite allows unauthenticated attackers to compromise mailbox data and impersonate users via forged share notifications.

Executive summary

A critical stored cross-site scripting vulnerability in Zimbra Collaboration Suite (ZCS) allows unauthenticated attackers to hijack user sessions and access sensitive mailbox data.

Vulnerability

This vulnerability is a stored cross-site scripting (CWE-79) flaw triggered when a user interacts with a malicious share notification. An unauthenticated attacker can forge this notification to execute arbitrary scripts in the context of an authenticated recipient.

Business impact

The exploitation of this vulnerability allows for unauthorized access to sensitive user communications, potential data exfiltration, and full account impersonation. Given the CVSS score of 9.3, this represents a critical risk to organizational confidentiality and integrity, as attackers can leverage the victim's session to perform actions on their behalf within the mail environment.

Remediation

Immediate Action: Update Zimbra Collaboration Suite (ZCS) to version 10.1.21 or later immediately to apply the vendor-provided patch.

Proactive Monitoring: Review web server access logs for anomalous share notification requests and monitor for suspicious script execution patterns within the Zimbra Modern web interface.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to inspect and sanitize incoming share notification payloads and restrict access to the mail interface from untrusted or external sources where possible.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

The high severity of this vulnerability, combined with the potential for full account takeover, necessitates an immediate patching cycle. Organizations should prioritize updating all instances of Zimbra Collaboration Suite to version 10.1.21 or later to eliminate the risk of stored cross-site scripting and unauthorized mailbox access.

More Zimbra CVEs

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief critical section

Sources

Originally found and disclosed by Jonah Burgess (CryptoCat), Senior Security Researcher, Rapid7, per the CVE Program record.