CVE-2026-50054: Zimbra Collaboration Suite GrantRightsRequest SOAP Handler Allows Self-Granting of Undocumented loginAs Mailbox Delegation Right
Published Oct 8, 2026
·Updated
An authorization flaw in Zimbra Collaboration Suite’s GrantRightsRequest allows an attacker with access to an authenticated account to grant another local account the loginAs right, creating persistent mailbox access and mail-sending authority that survives password changes and session expiry.
Affected Software
1 affected component
Zimbra Zimbra Collaboration Suite
Event History
Oct 8, 2026
CVE Published
via MITRE·04:25 PM
Data Sourced
via MITRE·04:25 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access is required to exploit this issue?
An attacker needs access to an authenticated Zimbra Collaboration Suite account. No user interaction is required.
2
What accounts can be targeted through this flaw?
The flaw allows the attacker to grant the loginAs delegation right to another local account. This creates access to that mailbox and authority to send mail as that mailbox.
3
Will changing passwords remove the unauthorized access?
No. The granted loginAs right persists through password changes and session expiry, creating persistent mailbox access.