CVE-2026-33369: Input Validation
Zimbra Collaboration (ZCS) 10.0 and 10.1 contains an LDAP injection vulnerability in the Mailbox SOAP service within a FolderAction operation. The application fails to properly sanitize user-supplied input before incorporating it into an LDAP search filter. An authenticated attacker can exploit this issue by sending a crafted SOAP request that manipulates the LDAP query, allowing retrieval of sensitive directory attributes.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33369?
CVE-2026-33369 is considered a high severity vulnerability due to its potential for LDAP injection by an authenticated attacker.
How do I fix CVE-2026-33369?
To fix CVE-2026-33369, upgrade to Zimbra Collaboration (ZCS) versions 10.2 or later where the vulnerability is addressed.
What types of systems are affected by CVE-2026-33369?
CVE-2026-33369 affects Zimbra Collaboration (ZCS) versions 10.0 and 10.1.
What is an LDAP injection vulnerability in the context of CVE-2026-33369?
An LDAP injection vulnerability like CVE-2026-33369 occurs when user input is improperly sanitized before being used in an LDAP search filter, allowing an attacker to manipulate the queries.
Who can exploit CVE-2026-33369?
CVE-2026-33369 can be exploited by authenticated attackers who can supply malicious input to the Mailbox SOAP service.