LOWVulnerability

CVE-2026-73575

In Zimbra Collaboration (ZCS) before 10.1.17, a Cross-Site Request Forgery (CSRF) vulnerability exists in the Exchange Web Services (EWS) endpoint of Zimbra Collaboration (ZCS) due to insufficient validation of request content types. An attacker can exploit this vulnerability by causing an authenticated user to submit a crafted request, potentially allowing unauthorized actions to be performed on behalf of the victim.

Properties

severity
LOW
score
3.1
cve_id
CVE-2026-73575
vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
published_at
2026-08-13T16:19:06.767
last_modified
2026-08-21T14:05:53.253

Related Entities (2)

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (1)

[Weakness]Cross-Site Request Forgery (CSRF)

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-73575 — Ninja Signal Threat Intelligence | Ninja Signal