CVE-2026-73573
published 2026-08-13CVE-2026-73573: In Zimbra Collaboration (ZCS) before 10.1.17, a path traversal vulnerability exists in the Zimbra Briefcase document editing functionality due to improper…
PriorityP415low3.1CVSS 3.1
AVNACHPRLUINSUCLINAN
EPSS
0.25%
16.9th percentile
In Zimbra Collaboration (ZCS) before 10.1.17, a path traversal vulnerability exists in the Zimbra Briefcase document editing functionality due to improper validation of the packages parameter. An authenticated attacker can exploit this vulnerability by supplying a crafted path traversal sequence, potentially allowing unauthorized disclosure of sensitive files within the web application directory.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| zimbra | collaboration | < 10.1.17 | 10.1.17 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Zimbra Collaboration up to 10.1.16 Briefcase packages path traversal (WID-SEC-2026-1735)
vuldb·2026-08-16·CVSS 3.1
CVE-2026-73573 [LOW] Zimbra Collaboration up to 10.1.16 Briefcase packages path traversal (WID-SEC-2026-1735)
A vulnerability has been found in Zimbra Collaboration up to 10.1.16 and classified as problematic. This affects an unknown function of the component Briefcase. Performing a manipulation of the argument packages results in path traversal.
This vulnerability is known as CVE-2026-73573. Remote exploitation of the attack is possible. No exploit is available.
The affected component should be upgraded.
GHSA
In Zimbra Collaboration (ZCS) before 10.1.17, a path traversal vulnerability exists in the Zimbra Briefcase document editing functionality due to improper validation of the packages parameter.
ghsa_unreviewed·2026-08-13
CVE-2026-73573 [LOW] CWE-24 In Zimbra Collaboration (ZCS) before 10.1.17, a path traversal vulnerability exists in the Zimbra Briefcase document editing functionality due to improper validation of the packages parameter.
In Zimbra Collaboration (ZCS) before 10.1.17, a path traversal vulnerability exists in the Zimbra Briefcase document editing functionality due to improper validation of the packages parameter. An authenticated attacker can exploit this vulnerability by supplying a crafted path traversal sequence, potentially allowing unauthorized disclosure of sensitive files within the web application directory.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-13
Published