CVE-2026-33371: XEE
An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. An XML External Entity (XXE) vulnerability exists in the Zimbra Exchange Web Services (EWS) SOAP interface due to improper handling of XML input. An authenticated attacker can submit crafted XML data that is processed by an XML parser with external entity resolution enabled. Successful exploitation may allow disclosure of sensitive local files from the server.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33371?
CVE-2026-33371 is classified as a medium severity vulnerability due to its potential to allow authenticated attackers to exploit XML input.
How do I fix CVE-2026-33371?
To mitigate CVE-2026-33371, upgrade Zimbra Collaboration to version 10.2 or later where this issue is resolved.
What software is affected by CVE-2026-33371?
CVE-2026-33371 specifically affects Zimbra Collaboration (ZCS) versions 10.0 and 10.1.
What type of vulnerability is CVE-2026-33371?
CVE-2026-33371 is an XML External Entity (XXE) vulnerability due to improper handling of XML input in Zimbra's EWS SOAP interface.
Who can exploit CVE-2026-33371?
Authenticated attackers can exploit CVE-2026-33371 by submitting specially crafted XML data to the affected Zimbra systems.