
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-73576 is a weak cryptographic key generation vulnerability in the OnlyOffice integration of Zimbra Collaboration (ZCS). The zimbraDocumentEditingJwtSecret is generated using an insecure (non-cryptographically secure) random number generator, resulting in insufficient entropy. An attacker who obtains a JWT signed with this secret may recover the signing key via offline brute-force and subsequently forge JWTs. All ZCS versions before 10.1.17 are affected. It carries a CVSS v3.1 base score of 6.3 (Medium) (GitHub Advisory, Zimbra Security Advisories).
The root cause is classified as CWE-1241 (Use of Predictable Algorithm in Random Number Generator). Zimbra's OnlyOffice integration generates the zimbraDocumentEditingJwtSecret — used to sign JWTs for document editing sessions — with a predictable pseudo-random number generator that produces insufficient entropy. An authenticated attacker with low privileges can obtain a legitimately signed JWT (e.g., by accessing the document editing feature), then perform an offline brute-force or cryptanalytic attack (CAPEC-97: Cryptanalysis) against the weak secret to recover it. Once the secret is known, the attacker can forge arbitrary JWTs, bypassing authentication controls for the OnlyOffice integration. Exploitation requires network access and low-level authentication, but no user interaction (GitHub Advisory).
Successful exploitation allows an authenticated attacker to forge JWTs and impersonate arbitrary users within the Zimbra OnlyOffice document editing functionality. The primary impact is a high integrity loss — forged tokens could grant unauthorized access to documents, enable unauthorized edits, or facilitate privilege escalation within the document editing subsystem. Confidentiality and availability are not directly impacted by this vulnerability, though forged access to sensitive documents could lead to indirect data exposure (GitHub Advisory, Zimbra Security Advisories).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (GitHub Advisory). The NVD SSVC assessment classifies exploitation as "none" and the attack as non-automatable, reflecting the requirement for an attacker to first obtain a valid JWT before attempting offline brute-force. The EPSS score is approximately 0.188% (9th percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Qualys has added detection for this CVE (Detection ID 532191).
hashcat with JWT mode, or jwt_tool) to perform an offline dictionary or brute-force attack against the captured JWT, exploiting the low entropy of the zimbraDocumentEditingJwtSecret.zimbraDocumentEditingJwtSecret configuration attribute.Upgrade Zimbra Collaboration to version 10.1.17 or later, which addresses the weak key generation by using a cryptographically secure random number generator for zimbraDocumentEditingJwtSecret (Zimbra Security Advisories, GitHub Advisory). As an additional remediation step on affected systems, administrators should manually rotate the zimbraDocumentEditingJwtSecret to a value generated by a cryptographically secure source after upgrading. If immediate upgrade is not possible, consider disabling the OnlyOffice document editing integration until patching can be completed.
The vulnerability was disclosed by Zimbra on August 13, 2026, via their Security Advisories wiki and the GitHub Advisory Database. Coverage has been limited to automated vulnerability tracking platforms such as VulDB, CVEFeed, and INCIBE-CERT, with no notable independent researcher commentary or significant social media discussion observed at this time (Zimbra Security Advisories).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."