CVE-2026-73576
published 2026-08-13CVE-2026-73576: In Zimbra Collaboration (ZCS) before 10.1.17, weak cryptographic key generation vulnerability exists in the OnlyOffice integration. The…
PriorityP336medium6.3CVSS 3.1
AVNACHPRLUINSCCNIHAN
EPSS
0.19%
8.8th percentile
In Zimbra Collaboration (ZCS) before 10.1.17, weak cryptographic key generation vulnerability exists in the OnlyOffice integration. The zimbraDocumentEditingJwtSecret is generated using an insecure random number generator, resulting in insufficient entropy. An attacker who obtains a JWT signed with the generated secret may be able to recover the JWT signing secret through offline brute-force, potentially enabling JWT forgery.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| zimbra | collaboration | < 10.1.17 | 10.1.17 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Zimbra Collaboration up to 10.1.16 OnlyOffice Integration zimbraDocumentEditingJwtSecret entropy (WID-SEC-2026-1735)
vuldb·2026-08-16·CVSS 6.3
CVE-2026-73576 [MEDIUM] Zimbra Collaboration up to 10.1.16 OnlyOffice Integration zimbraDocumentEditingJwtSecret entropy (WID-SEC-2026-1735)
A vulnerability classified as problematic was found in Zimbra Collaboration up to 10.1.16. This affects an unknown function of the component OnlyOffice Integration. Such manipulation of the argument zimbraDocumentEditingJwtSecret leads to insufficient entropy.
This vulnerability is documented as CVE-2026-73576. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is advised.
GHSA
In Zimbra Collaboration (ZCS) before 10.1.17, weak cryptographic key generation vulnerability exists in the OnlyOffice integration.
ghsa_unreviewed·2026-08-13
CVE-2026-73576 [MEDIUM] CWE-1241 In Zimbra Collaboration (ZCS) before 10.1.17, weak cryptographic key generation vulnerability exists in the OnlyOffice integration.
In Zimbra Collaboration (ZCS) before 10.1.17, weak cryptographic key generation vulnerability exists in the OnlyOffice integration. The zimbraDocumentEditingJwtSecret is generated using an insecure random number generator, resulting in insufficient entropy. An attacker who obtains a JWT signed with the generated secret may be able to recover the JWT signing secret through offline brute-force, potentially enabling JWT forgery.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-13
Published