---
id: CVE-2026-73571
title: >-
  An authorization bypass vulnerability exists in Zimbra Collaboration (ZCS)
  before 10.1.17 due to improper authorization validation in delegated email
  sending functionality
summary: >-
  An authorization bypass vulnerability exists in Zimbra Collaboration (ZCS)
  before 10.1.17 due to improper authorization validation in delegated email
  sending functionality. An authenticated attacker can send specially crafted
  SOAP reques…
severity: low
cvss: 3.1
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-863
published: '2026-08-13'
updated: '2026-08-21'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-73571'
references:
  - url: 'https://wiki.zimbra.com/wiki/Security_Center'
    label: cve@mitre.org
  - url: 'https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories'
    label: cve@mitre.org
tags:
  - nvd
epss: 0.00155
epssPercentile: 0.04993
ingestedAt: '2026-08-22T13:32:36.123Z'
---

## Overview

An authorization bypass vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.17 due to improper authorization validation in delegated email sending functionality. An authenticated attacker can send specially crafted SOAP requests to impersonate another user and send emails without possessing the required delegation or send-as permissions. This occurs in the SaveDraftRequest SOAP handler.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
