CVE-2026-73573
Zimbra Collaboration Server vulnerability analysis and mitigation

Overview

CVE-2026-73573 is a path traversal vulnerability in Zimbra Collaboration (ZCS) affecting the Briefcase document editing functionality. It exists due to improper validation of the packages parameter, allowing an authenticated attacker to supply crafted ../ sequences to read sensitive files within the web application directory. All ZCS versions before 10.1.17 are affected; version 10.1.17 and later contain the fix. The vulnerability was published on August 13, 2026, with a CVSS v3.1 base score of 3.1 (Low) (GitHub Advisory, Zimbra Security Advisories).

Technical details

The root cause is classified as CWE-24 (Path Traversal: '../filedir'), where the application fails to properly neutralize ../ sequences in the packages parameter used by the Briefcase document editing feature (GitHub Advisory). An authenticated attacker with low privileges can send a crafted network request containing a path traversal sequence to traverse outside the intended web application directory and read arbitrary files accessible to the web server process. Exploitation requires authentication (low privilege level) and has high attack complexity, meaning specific conditions or non-default configurations must be present for successful exploitation.

Impact

Successful exploitation results in unauthorized disclosure of sensitive files within the Zimbra web application directory, impacting confidentiality only — there is no integrity or availability impact. An attacker could potentially read configuration files, credentials, or other sensitive data stored within the web application's directory tree. The scope is limited to the affected Zimbra instance, with no direct mechanism for lateral movement inherent to this vulnerability (GitHub Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (GitHub Advisory). The NVD SSVC assessment confirms exploitation status as "none" and technical impact as "partial." The EPSS score is approximately 0.253% (17th percentile), indicating a low probability of exploitation within the next 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no threat actor attribution has been reported.

Exploitation steps

  1. Authentication: Obtain valid Zimbra user credentials with at least low-privilege access to the ZCS instance running a version prior to 10.1.17.
  2. Identify target endpoint: Locate the Briefcase document editing functionality within the Zimbra web interface, which processes the vulnerable packages parameter.
  3. Craft malicious request: Construct an HTTP request to the Briefcase document editing endpoint, injecting a path traversal sequence (e.g., ../../../../etc/passwd or similar) into the packages parameter.
  4. Submit request: Send the crafted request to the target ZCS server over the network.
  5. Retrieve file contents: If the traversal succeeds, the server returns the contents of the targeted file from outside the intended web application directory, disclosing sensitive information (GitHub Advisory).

Indicators of compromise

  • Network: Unusual HTTP requests to Zimbra Briefcase document editing endpoints containing encoded or plaintext ../ sequences in the packages parameter.
  • Logs: Zimbra application or web server access logs showing requests with path traversal patterns (e.g., %2e%2e%2f, ../, ..%2f) in the packages parameter; HTTP 200 responses to such requests may indicate successful file disclosure.
  • File System: No direct file system artifacts expected from read-only exploitation, but review of web server process file access logs (e.g., via auditd on Linux) may reveal access to files outside the web application directory.

Mitigation and workarounds

Zimbra has released version 10.1.17 which addresses this vulnerability; upgrading to ZCS 10.1.17 or later is the recommended remediation (Zimbra Security Advisories, GitHub Advisory). As interim mitigations, administrators should restrict access to the Briefcase document editing functionality to trusted users only, implement network-level access controls to limit exposure of the Zimbra web application, and monitor application logs for suspicious path traversal attempts in the packages parameter.

Additional resources


SourceThis report was generated using AI

Related Zimbra Collaboration Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-73576MEDIUM6.3
  • Zimbra Collaboration Server logoZimbra Collaboration Server
  • cpe:2.3:a:zimbra:collaboration
NoYesAug 13, 2026
CVE-2026-73572MEDIUM6.1
  • Zimbra Collaboration Server logoZimbra Collaboration Server
  • cpe:2.3:a:zimbra:collaboration
NoYesAug 13, 2026
CVE-2026-73575LOW3.1
  • Zimbra Collaboration Server logoZimbra Collaboration Server
  • cpe:2.3:a:zimbra:collaboration
NoYesAug 13, 2026
CVE-2026-73574LOW3.1
  • Zimbra Collaboration Server logoZimbra Collaboration Server
  • cpe:2.3:a:zimbra:collaboration
NoYesAug 13, 2026
CVE-2026-73573LOW3.1
  • Zimbra Collaboration Server logoZimbra Collaboration Server
  • cpe:2.3:a:zimbra:collaboration
NoYesAug 13, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management