CVE-2026-50055: Zimbra Collaboration Suite Sieve Notify Filter Action Bypasses Mail Forwarding Restriction via Variable Expansion
Published Oct 8, 2026
·Updated
A policy-enforcement flaw in Zimbra Collaboration Suite allows an authenticated user to bypass disabled mail forwarding by using a Sieve notify action to send copies of email content and headers to an arbitrary address.
Affected Software
1 affected component
Zimbra Zimbra Collaboration Suite
Event History
Oct 8, 2026
CVE Published
via MITRE·04:25 PM
Data Sourced
via MITRE·04:25 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An authenticated Zimbra Collaboration Suite user can exploit it. The user needs the ability to configure a Sieve filter using the notify action.
2
Does disabling mail forwarding prevent exploitation?
No. The flaw specifically bypasses the disabled mail-forwarding restriction by using Sieve notify with variable expansion to send email content and headers to an arbitrary address.
3
What information could be exposed?
Copies of email content and headers can be sent to an arbitrary external address. The provided information does not indicate an integrity or availability impact.