What is CVE-2026-73573?
CVE-2026-73573 is a path traversal vulnerability found in the Zimbra Briefcase document editing functionality of Zimbra Collaboration (ZCS) due to improper validation of the 'packages' parameter. An authenticated attacker can exploit this flaw by sending a crafted path traversal sequence to perform unauthorized file operations on the server. Users should immediately update to ZCS version 10.1.17 or later.
Azərbaycanca: CVE-2026-73573 Zimbra Collaboration Suite (ZCS) proqramında 'Briefcase' sənəd redaktə funksiyasında aşkarlanmış path traversal zəifliyidir. Bu boşluq 'packages' parametrinin düzgün yoxlanılmaması səbəbindən autentifikasiya olunmuş hücumçuya xüsusi hazırlanmış sorğu ilə serverdə fayl əməliyyatları aparmağa imkan verir. ZCS istifadəçiləri dərhal 10.1.17 və ya daha yeni versiyaya yeniləmə etməlidir.
Related CVEs
link basis: same weakness class CWE-22; shared vendor: Zimbra
FAQ2
In which component of Zimbra was CVE-2026-73573 discovered?
CVE-2026-73573 was discovered in the 'Briefcase' document editing functionality of Zimbra Collaboration Suite (ZCS).
Which ZCS version should users update to in order to remediate this path traversal vulnerability?
Users should update to ZCS version 10.1.17 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.