CVE-2026-50054: Zimbra Collaboration Suite GrantRightsRequest SOAP Handler Allows Self-Granting of Undocumented loginAs Mailbox Delegation Right

Published Oct 8, 2026
·
Updated

An authorization flaw in Zimbra Collaboration Suite’s GrantRightsRequest allows an attacker with access to an authenticated account to grant another local account the loginAs right, creating persistent mailbox access and mail-sending authority that survives password changes and session expiry.

Affected Software

1 affected component
Zimbra Zimbra Collaboration Suite

Event History

Oct 8, 2026
CVE Published
via MITRE·04:25 PM
Data Sourced
via MITRE·04:25 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What level of access is required to exploit this issue?

An attacker needs access to an authenticated Zimbra Collaboration Suite account. No user interaction is required.

2

What accounts can be targeted through this flaw?

The flaw allows the attacker to grant the loginAs delegation right to another local account. This creates access to that mailbox and authority to send mail as that mailbox.

3

Will changing passwords remove the unauthorized access?

No. The granted loginAs right persists through password changes and session expiry, creating persistent mailbox access.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203