What is CVE-2026-73571?
An authorization bypass vulnerability in Zimbra Collaboration Suite (ZCS) before version 10.1.17 allows an authenticated attacker to send crafted SOAP requests and impersonate other users via the delegated email sending functionality. Upgrading ZCS to the latest version is advised to mitigate this risk.
Azərbaycanca: Zimbra Collaboration Suite (ZCS) proqramında "delegated email sending" funksiyasında səlahiyyət yoxlamasının düzgün aparılmaması səbəbindən identifikasiya olunmuş hücumçu xüsusi SOAP sorğuları vasitəsilə digər istifadəçilərin adından e-poçt göndərə bilər. Bu, 10.1.17 versiyasından əvvəlki ZCS məhsullarına təsir edir. ZCS-in ən son versiyaya yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
Which versions of Zimbra Collaboration Suite are affected by CVE-2026-73571?
The vulnerability affects ZCS products prior to version 10.1.17.
How can CVE-2026-73571 be exploited?
An authenticated attacker can exploit the authorization bypass in the delegated email sending functionality by sending crafted SOAP requests to impersonate other users.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.