
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-73575 is a Cross-Site Request Forgery (CSRF) vulnerability in the Exchange Web Services (EWS) endpoint of Zimbra Collaboration (ZCS) caused by insufficient validation of request content types. It affects all ZCS versions before 10.1.17. The vulnerability was published on August 13, 2026, with a patch available in version 10.1.17. It carries a CVSS v3.1 base score of 3.1 (Low) (GitHub Advisory).
The root cause is classified as CWE-352 (Cross-Site Request Forgery), stemming from the EWS endpoint's failure to adequately validate the content type of incoming requests. Because the endpoint does not enforce strict content-type checks, an attacker can craft a malicious web page or link that, when visited by an authenticated Zimbra user, causes the victim's browser to submit an unintended request to the EWS endpoint. Exploitation requires user interaction (the victim must be tricked into visiting a crafted page) and has high attack complexity, limiting its practical exploitability (GitHub Advisory).
Successful exploitation allows an unauthenticated attacker to perform unauthorized actions on behalf of an authenticated Zimbra user through the EWS endpoint, resulting in a low integrity impact. There is no confidentiality or availability impact associated with this vulnerability. The scope is unchanged, meaning the impact is confined to the Zimbra Collaboration instance itself without enabling lateral movement to other systems (GitHub Advisory).
There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.112% (2nd percentile), indicating a low probability of exploitation within the next 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and NVD's SSVC assessment confirms exploitation status as "none" (GitHub Advisory).
/ews/Exchange.asmx or similar) originating from unusual referrer URLs or external origins.Content-Type headers (e.g., text/plain or application/x-www-form-urlencoded instead of expected SOAP/XML types) from authenticated user sessions.The primary remediation is to upgrade Zimbra Collaboration to version 10.1.17 or later, which addresses the insufficient content-type validation in the EWS endpoint (GitHub Advisory, Zimbra Security Advisories). As interim mitigations, administrators should implement SameSite=Strict or SameSite=Lax cookie attributes to reduce CSRF risk, enforce strict Content-Type validation at the web application firewall or reverse proxy layer, and add security headers such as X-Frame-Options to prevent clickjacking. Users should also be advised not to click suspicious links while authenticated to Zimbra.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."