CVE-2026-73574
CVE-2026-73574 is a low-severity vulnerability in Synacor Zimbra Collaboration Suite with a CVSS 3.x base score of 3.1. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-669.
Key facts
- Severity: Low (CVSS 3.x base score 3.1)
- EPSS exploit prediction: 0% (24th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-669
- Affected product: Synacor Zimbra Collaboration Suite
- Published:
- Last modified:
Description
In Zimbra Collaboration before 10.1.17, a local file inclusion (LFI) vulnerability exists in the Zimbra Classic Web Client due to improper validation of the fu request parameter. An unauthenticated attacker can exploit this vulnerability by supplying a crafted path, potentially allowing unauthorized disclosure of protected files, such as WEB-INF/web.xml, within the web application directory. This occurs in the Forward servlet.
Frequently asked questions
- What is CVE-2026-73574?
- In Zimbra Collaboration before 10.1.17, a local file inclusion (LFI) vulnerability exists in the Zimbra Classic Web Client due to improper validation of the fu request parameter. An unauthenticated attacker can exploit this vulnerability by supplying a crafted path, potentially allowing unauthorized disclosure of protected files, such as WEB-INF/web.xml, within the web application directory. This occurs in the Forward servlet.
- How severe is CVE-2026-73574?
- CVE-2026-73574 has a CVSS 3.x base score of 3.1, rated low severity. It is exploitable over network with high attack complexity, requires low privileges and no user interaction. Impact on confidentiality is low, integrity none, and availability none.
- Is CVE-2026-73574 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (24th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-73574?
- CVE-2026-73574 affects Synacor Zimbra Collaboration Suite. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-73574?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-73574 published?
- CVE-2026-73574 was published on 2026-08-13 and last updated on 2026-08-28.
References
- https://wiki.zimbra.com/wiki/Zimbra_Responsible_Disclosure_Policy
- https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories
Affected products (1)
- cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:*
More vulnerabilities in Synacor Zimbra Collaboration Suite
- CVE-2024-45519 — Critical (CVSS 10.0): The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before…
- CVE-2022-41352 — Critical (CVSS 9.8): An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through…
- CVE-2022-37042 — Critical (CVSS 9.8): Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts…
- CVE-2020-7796 — Critical (CVSS 9.8): Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7 allows SSRF when WebEx zimlet is installed and zimlet JSP is…
- CVE-2019-9670 — Critical (CVSS 9.8): mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection…
- CVE-2019-6980 — Critical (CVSS 9.8): Synacor Zimbra Collaboration Suite 8.7.x through 8.8.11 allows insecure object deserialization in the IMAP component.
All CVEs affecting Synacor Zimbra Collaboration Suite →
Other CWE-669 vulnerabilities
- CVE-2021-30120 — Critical (CVSS 9.9): Kaseya VSA before 9.5.7 allows attackers to bypass the 2FA requirement. The need to use 2FA for authentication in…
- CVE-2025-67895 — Critical (CVSS 9.8): Edge3 Worker RPC RCE on Airflow 2. This issue affects Apache Airflow Providers Edge3: before 2.0.0 - and only if you…
- CVE-2022-4446 — Critical (CVSS 9.8): PHP Remote File Inclusion in GitHub repository tsolucio/corebos prior to 8.0.
- CVE-2020-24683 — Critical (CVSS 9.8): The affected versions of S+ Operations (version 2.1 SP1 and earlier) used an approach for user authentication which…
- CVE-2020-5800 — Critical (CVSS 9.8): The Eat Spray Love mobile app for both iOS and Android contains logic that allows users to bypass authentication and…
- CVE-2020-15892 — Critical (CVSS 9.8): An issue was discovered in apply.cgi on D-Link DAP-1520 devices before 1.10b04Beta02. Whenever a user performs a login…