
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-73573 is a path traversal vulnerability in Zimbra Collaboration (ZCS) affecting the Briefcase document editing functionality. It exists due to improper validation of the packages parameter, allowing an authenticated attacker to supply crafted ../ sequences to read sensitive files within the web application directory. All ZCS versions before 10.1.17 are affected; version 10.1.17 and later contain the fix. The vulnerability was published on August 13, 2026, with a CVSS v3.1 base score of 3.1 (Low) (GitHub Advisory, Zimbra Security Advisories).
The root cause is classified as CWE-24 (Path Traversal: '../filedir'), where the application fails to properly neutralize ../ sequences in the packages parameter used by the Briefcase document editing feature (GitHub Advisory). An authenticated attacker with low privileges can send a crafted network request containing a path traversal sequence to traverse outside the intended web application directory and read arbitrary files accessible to the web server process. Exploitation requires authentication (low privilege level) and has high attack complexity, meaning specific conditions or non-default configurations must be present for successful exploitation.
Successful exploitation results in unauthorized disclosure of sensitive files within the Zimbra web application directory, impacting confidentiality only — there is no integrity or availability impact. An attacker could potentially read configuration files, credentials, or other sensitive data stored within the web application's directory tree. The scope is limited to the affected Zimbra instance, with no direct mechanism for lateral movement inherent to this vulnerability (GitHub Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (GitHub Advisory). The NVD SSVC assessment confirms exploitation status as "none" and technical impact as "partial." The EPSS score is approximately 0.253% (17th percentile), indicating a low probability of exploitation within the next 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no threat actor attribution has been reported.
packages parameter.../../../../etc/passwd or similar) into the packages parameter.../ sequences in the packages parameter.%2e%2e%2f, ../, ..%2f) in the packages parameter; HTTP 200 responses to such requests may indicate successful file disclosure.Zimbra has released version 10.1.17 which addresses this vulnerability; upgrading to ZCS 10.1.17 or later is the recommended remediation (Zimbra Security Advisories, GitHub Advisory). As interim mitigations, administrators should restrict access to the Briefcase document editing functionality to trusted users only, implement network-level access controls to limit exposure of the Zimbra web application, and monitor application logs for suspicious path traversal attempts in the packages parameter.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."