CVE-2026-73574
published 2026-08-13CVE-2026-73574: In Zimbra Collaboration before 10.1.17, a local file inclusion (LFI) vulnerability exists in the Zimbra Classic Web Client due to improper validation of the fu…
PriorityP415low3.1CVSS 3.1
AVNACHPRLUINSUCLINAN
EPSS
0.20%
10.4th percentile
In Zimbra Collaboration before 10.1.17, a local file inclusion (LFI) vulnerability exists in the Zimbra Classic Web Client due to improper validation of the fu request parameter. An unauthenticated attacker can exploit this vulnerability by supplying a crafted path, potentially allowing unauthorized disclosure of protected files, such as WEB-INF/web.xml, within the web application directory. This occurs in the Forward servlet.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| zimbra | collaboration | < 10.1.17 | 10.1.17 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Zimbra Collaboration up to 10.1.16 Classic Web Client WEB-INF/web.xml Forward servlet fu file inclusion (WID-SEC-2026-1735)
vuldb·2026-08-16·CVSS 3.1
CVE-2026-73574 [LOW] Zimbra Collaboration up to 10.1.16 Classic Web Client WEB-INF/web.xml Forward servlet fu file inclusion (WID-SEC-2026-1735)
A vulnerability classified as problematic has been found in Zimbra Collaboration up to 10.1.16. The impacted element is the function Forward servlet of the file WEB-INF/web.xml of the component Classic Web Client. This manipulation of the argument fu causes file inclusion.
This vulnerability is registered as CVE-2026-73574. Remote exploitation of the attack is possible. No exploit is available.
It is recommended to upgrade the affected component.
GHSA
In Zimbra Collaboration before 10.1.17, a local file inclusion (LFI) vulnerability exists in the Zimbra Classic Web Client due to improper validation of the fu request parameter.
ghsa_unreviewed·2026-08-13
CVE-2026-73574 [LOW] CWE-669 In Zimbra Collaboration before 10.1.17, a local file inclusion (LFI) vulnerability exists in the Zimbra Classic Web Client due to improper validation of the fu request parameter.
In Zimbra Collaboration before 10.1.17, a local file inclusion (LFI) vulnerability exists in the Zimbra Classic Web Client due to improper validation of the fu request parameter. An unauthenticated attacker can exploit this vulnerability by supplying a crafted path, potentially allowing unauthorized disclosure of protected files, such as WEB-INF/web.xml, within the web application directory. This occurs in the Forward servlet.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-13
Published