CVE-2023-26562: Medium severity zimbra collaboration suite vulnerability
In Zimbra Collaboration (ZCS) 8.8.15 and 9.0, a closed account (with 2FA and generated passwords) can send e-mail messages when configured for Imap/smtp.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-26562?
CVE-2023-26562 has been classified as a medium severity vulnerability due to its potential exploitation by unauthorized users.
How do I fix CVE-2023-26562?
To remediate CVE-2023-26562, upgrade to the latest version of Zimbra Collaboration that addresses this vulnerability.
What systems are affected by CVE-2023-26562?
CVE-2023-26562 affects Zimbra Collaboration versions 8.8.15 and 9.0.
Can a closed account exploit CVE-2023-26562?
Yes, a closed account with two-factor authentication can still send email messages if configured for IMAP/SMTP, leading to potential exploitation.
Is two-factor authentication sufficient protection against CVE-2023-26562?
No, two-factor authentication alone is not sufficient as this vulnerability allows closed accounts to send emails, bypassing the expected restrictions.