CVE-2026-50055Medium· 6.5▾ TwilightPoC availableA policy-enforcement flaw in Zimbra Collaboration Suite allows an authenticated user to bypass disabled mail forwarding by using a Sieve notify action to send copies of email content and headers to an arbitrary address.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 35.8 · likelihood 0 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CVEORG
1 GitHub repo (last check)
A policy-enforcement flaw in Zimbra Collaboration Suite allows an authenticated user to bypass disabled mail forwarding by using a Sieve notify action to send copies of email content and headers to an arbitrary address.
collaboration_suite < 10.1.20Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-10631Medium· 6.5Zimbra Collaboration Suite EWS Extension Authorization Bypass via Crafted Composite Folder/Item Identifier
CVE-2026-50054High· 7.1Zimbra Collaboration Suite GrantRightsRequest SOAP Handler Allows Self-Granting of Undocumented loginAs Mailbox Delegation Right
CVE-2026-93643Critical· 9.8When OnlyOffice/Document Editing is available, an unauthenticated remote attacker with access to an existing supported public Briefcase document can abuse unsigned save fields to perform path-traversal writes and execute commands as zimbra.
CVE-2026-93642Critical· 9.3An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Modern recipient clicks Accept Share, allowing the attacker to access mailbox data and act as the victim.
CVE-2026-93641Critical· 9.3An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Classic recipient clicks Accept Share, allowing the attacker to access mailbox data and act as the victim.
CVE-2026-93647Critical· 9.3An unauthenticated calendar sender can place active markup in a COUNTER message's RFC From address