CVE-2026-33372: CSRF
An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A cross-site request forgery (CSRF) vulnerability exists in Zimbra Webmail due to improper validation of CSRF tokens. The application accepts CSRF tokens supplied within the request body instead of requiring them through the expected request header. An attacker can exploit this issue by tricking an authenticated user into submitting a crafted request. This may allow unauthorized actions to be performed on behalf of the victim.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33372?
CVE-2026-33372 has a medium severity rating due to its potential exploitation through cross-site request forgery.
How do I fix CVE-2026-33372?
To mitigate CVE-2026-33372, users should update their Zimbra Collaboration to the latest version that addresses the CSRF vulnerability.
What versions of Zimbra Collaboration are affected by CVE-2026-33372?
CVE-2026-33372 affects Zimbra Collaboration versions 10.0 and 10.1.
What is the nature of the vulnerability in CVE-2026-33372?
CVE-2026-33372 is a cross-site request forgery vulnerability caused by improper validation of CSRF tokens.
Can CVE-2026-33372 lead to unauthorized actions in Zimbra Webmail?
Yes, CVE-2026-33372 can allow attackers to perform unauthorized actions in Zimbra Webmail by exploiting the CSRF vulnerability.