---
id: CVE-2026-50054
title: >-
  An authorization flaw in Zimbra Collaboration Suite’s GrantRightsRequest
  allows an attacker with access to an authenticated account to grant another
  local account the loginAs right, creating persistent mailbox access and
  mail-sending aut…
summary: >-
  An authorization flaw in Zimbra Collaboration Suite’s GrantRightsRequest
  allows an attacker with access to an authenticated account to grant another
  local account the loginAs right, creating persistent mailbox access and
  mail-sending aut…
severity: high
cvss: 7.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N'
cwe:
  - CWE-269
vendor: Zimbra
product: Zimbra Collaboration Suite
affected:
  - collaboration_suite < 10.1.20
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T20:49:23.240'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-50054'
references:
  - url: 'https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories'
    label: cve@rapid7.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-08T16:52:14.786Z'
---

## Overview

An authorization flaw in Zimbra Collaboration Suite’s GrantRightsRequest allows an attacker with access to an authenticated account to grant another local account the loginAs right, creating persistent mailbox access and mail-sending authority that survives password changes and session expiry.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
