CVE-2026-33370: XSS
An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A stored cross-site scripting (XSS) vulnerability exists in the Zimbra Briefcase feature due to insufficient sanitization of specific uploaded file types. When a user opens a publicly shared Briefcase file containing malicious scripts, the embedded JavaScript executes in the context of the user's session. This allows an attacker to run arbitrary scripts, potentially leading to data exfiltration or other unauthorized actions on behalf of the victim user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33370?
CVE-2026-33370 is classified as a medium severity stored cross-site scripting vulnerability in Zimbra Collaboration.
How do I fix CVE-2026-33370?
To fix CVE-2026-33370, update Zimbra Collaboration to a version that addresses the XSS vulnerability.
What versions of Zimbra Collaboration are affected by CVE-2026-33370?
CVE-2026-33370 affects Zimbra Collaboration versions 10.0 and 10.1.
What is the impact of CVE-2026-33370?
The impact of CVE-2026-33370 allows attackers to execute malicious scripts in the context of an affected user's session.
Is CVE-2026-33370 related to file uploads in Zimbra?
Yes, CVE-2026-33370 is specifically related to insufficient sanitization of specific file types uploaded in the Zimbra Briefcase feature.