CVE-2026-73575
Zimbra Collaboration Server vulnerability analysis and mitigation

Overview

CVE-2026-73575 is a Cross-Site Request Forgery (CSRF) vulnerability in the Exchange Web Services (EWS) endpoint of Zimbra Collaboration (ZCS) caused by insufficient validation of request content types. It affects all ZCS versions before 10.1.17. The vulnerability was published on August 13, 2026, with a patch available in version 10.1.17. It carries a CVSS v3.1 base score of 3.1 (Low) (GitHub Advisory).

Technical details

The root cause is classified as CWE-352 (Cross-Site Request Forgery), stemming from the EWS endpoint's failure to adequately validate the content type of incoming requests. Because the endpoint does not enforce strict content-type checks, an attacker can craft a malicious web page or link that, when visited by an authenticated Zimbra user, causes the victim's browser to submit an unintended request to the EWS endpoint. Exploitation requires user interaction (the victim must be tricked into visiting a crafted page) and has high attack complexity, limiting its practical exploitability (GitHub Advisory).

Impact

Successful exploitation allows an unauthenticated attacker to perform unauthorized actions on behalf of an authenticated Zimbra user through the EWS endpoint, resulting in a low integrity impact. There is no confidentiality or availability impact associated with this vulnerability. The scope is unchanged, meaning the impact is confined to the Zimbra Collaboration instance itself without enabling lateral movement to other systems (GitHub Advisory).

Exploitability

There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.112% (2nd percentile), indicating a low probability of exploitation within the next 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and NVD's SSVC assessment confirms exploitation status as "none" (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify Zimbra Collaboration instances running versions prior to 10.1.17 that expose the EWS endpoint, using tools such as Shodan or Censys.
  2. Craft malicious request: Construct an HTML page or form that submits a cross-origin HTTP request to the target Zimbra EWS endpoint, exploiting the lack of content-type validation to bypass CSRF protections.
  3. Social engineering: Deliver the malicious link or page to an authenticated Zimbra user via phishing email, instant message, or other social engineering vector.
  4. Trigger victim interaction: When the authenticated victim visits the crafted page, their browser automatically submits the forged request to the EWS endpoint using the victim's active session credentials.
  5. Unauthorized action: The EWS endpoint processes the forged request as if it were legitimate, performing unauthorized actions (e.g., calendar manipulation, contact modification) on behalf of the victim (GitHub Advisory).

Indicators of compromise

  • Logs: Zimbra access logs showing unexpected or anomalous POST requests to the EWS endpoint (/ews/Exchange.asmx or similar) originating from unusual referrer URLs or external origins.
  • Network: HTTP requests to the EWS endpoint with mismatched or unexpected Content-Type headers (e.g., text/plain or application/x-www-form-urlencoded instead of expected SOAP/XML types) from authenticated user sessions.
  • Logs: Zimbra audit logs reflecting unexpected account actions (calendar changes, contact modifications, mail rule creation) that the user did not initiate, correlated with EWS endpoint activity.

Mitigation and workarounds

The primary remediation is to upgrade Zimbra Collaboration to version 10.1.17 or later, which addresses the insufficient content-type validation in the EWS endpoint (GitHub Advisory, Zimbra Security Advisories). As interim mitigations, administrators should implement SameSite=Strict or SameSite=Lax cookie attributes to reduce CSRF risk, enforce strict Content-Type validation at the web application firewall or reverse proxy layer, and add security headers such as X-Frame-Options to prevent clickjacking. Users should also be advised not to click suspicious links while authenticated to Zimbra.

Additional resources


SourceThis report was generated using AI

Related Zimbra Collaboration Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-73576MEDIUM6.3
  • Zimbra Collaboration Server logoZimbra Collaboration Server
  • cpe:2.3:a:zimbra:collaboration
NoYesAug 13, 2026
CVE-2026-73572MEDIUM6.1
  • Zimbra Collaboration Server logoZimbra Collaboration Server
  • cpe:2.3:a:zimbra:collaboration
NoYesAug 13, 2026
CVE-2026-73575LOW3.1
  • Zimbra Collaboration Server logoZimbra Collaboration Server
  • cpe:2.3:a:zimbra:collaboration
NoYesAug 13, 2026
CVE-2026-73574LOW3.1
  • Zimbra Collaboration Server logoZimbra Collaboration Server
  • cpe:2.3:a:zimbra:collaboration
NoYesAug 13, 2026
CVE-2026-73573LOW3.1
  • Zimbra Collaboration Server logoZimbra Collaboration Server
  • cpe:2.3:a:zimbra:collaboration
NoYesAug 13, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management