CVE-2026-73572
published 2026-08-13CVE-2026-73572: In Zimbra Collaboration (ZCS) before 10.1.17, a stored cross-site scripting (XSS) vulnerability exists in the Zimbra Classic Web Client due to insufficient…
PriorityP428medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.15%
5.1th percentile
In Zimbra Collaboration (ZCS) before 10.1.17, a stored cross-site scripting (XSS) vulnerability exists in the Zimbra Classic Web Client due to insufficient sanitization of specific attachment content during inline preview. An attacker can send a crafted email containing a malicious attachment that, when previewed by a user, executes arbitrary JavaScript within the victim's browser session. Successful exploitation may allow an attacker to perform unauthorized actions on behalf of the victim user, potentially leading to data exfiltration or unauthorized access to sensitive information.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| zimbra | collaboration | < 10.1.17 | 10.1.17 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Zimbra Collaboration up to 10.1.16 Inline Preview cross site scripting (WID-SEC-2026-1735)
vuldb·2026-08-16·CVSS 6.1
CVE-2026-73572 [MEDIUM] Zimbra Collaboration up to 10.1.16 Inline Preview cross site scripting (WID-SEC-2026-1735)
A vulnerability was found in Zimbra Collaboration up to 10.1.16. It has been rated as problematic. This issue affects some unknown processing of the component Inline Preview. Performing a manipulation results in cross site scripting.
This vulnerability was named CVE-2026-73572. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is advised.
GHSA
In Zimbra Collaboration (ZCS) before 10.1.17, a stored cross-site scripting (XSS) vulnerability exists in the Zimbra Classic Web Client due to insufficient sanitization of specific attachment content
ghsa_unreviewed·2026-08-13
CVE-2026-73572 [MEDIUM] CWE-79 In Zimbra Collaboration (ZCS) before 10.1.17, a stored cross-site scripting (XSS) vulnerability exists in the Zimbra Classic Web Client due to insufficient sanitization of specific attachment content
In Zimbra Collaboration (ZCS) before 10.1.17, a stored cross-site scripting (XSS) vulnerability exists in the Zimbra Classic Web Client due to insufficient sanitization of specific attachment content during inline preview. An attacker can send a crafted email containing a malicious attachment that, when previewed by a user, executes arbitrary JavaScript within the victim's browser session. Successful exploitation may allow an attacker to perform unauthorized actions on behalf of the victim user, potentially leading to data exfiltration or unauthorized access to sensitive information.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-13
Published