CVE-2026-50054High· 7.1▾ TwilightAn authorization flaw in Zimbra Collaboration Suite’s GrantRightsRequest allows an attacker with access to an authenticated account to grant another local account the loginAs right, creating persistent mailbox access and mail-sending aut…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
An authorization flaw in Zimbra Collaboration Suite’s GrantRightsRequest allows an attacker with access to an authenticated account to grant another local account the loginAs right, creating persistent mailbox access and mail-sending authority that survives password changes and session expiry.
collaboration_suite < 10.1.20Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-10631Medium· 6.5Zimbra Collaboration Suite EWS Extension Authorization Bypass via Crafted Composite Folder/Item Identifier
CVE-2026-50055Medium· 6.5Zimbra Collaboration Suite Sieve Notify Filter Action Bypasses Mail Forwarding Restriction via Variable Expansion
CVE-2026-93642Critical· 9.3An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Modern recipient clicks Accept Share, allowing the attacker to access mailbox data and act as the victim.
CVE-2026-93641Critical· 9.3An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Classic recipient clicks Accept Share, allowing the attacker to access mailbox data and act as the victim.
CVE-2026-93643Critical· 9.8When OnlyOffice/Document Editing is available, an unauthenticated remote attacker with access to an existing supported public Briefcase document can abuse unsigned save fields to perform path-traversal writes and execute commands as zimbra.
CVE-2026-93647Critical· 9.3An unauthenticated calendar sender can place active markup in a COUNTER message's RFC From address