CVE-2026-73570: OS Command Injection
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Zimbra Collaboration (ZCS)to a version that resolves this vulnerability.Fixed in 10.1.20 - Configuration
Disable SNMP notifications if SNMP notification processing is enabled (only relevant when the optional zimbra-snmp package is installed).
Zimbra Collaboration (ZCS) SNMP notifications SNMP notifications enabled = disabled - Compensating control
If zimbra-snmp is installed and SNMP notifications are enabled, ensure the service is not reachable from untrusted networks (network access control/segmentation) until SNMP notifications are disabled and/or ZCS is upgraded.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-73570?
The severity of CVE-2026-73570 is high with a CVSS score of 8.9.
How can I fix CVE-2026-73570?
To mitigate CVE-2026-73570, upgrade to Zimbra Collaboration version 10.1.20 or later and disable the optional zimbra-snmp package if not needed.
What impact does CVE-2026-73570 have on systems?
CVE-2026-73570 allows an unauthenticated attacker to execute remote code on affected Zimbra Collaboration servers.
What conditions need to be met for CVE-2026-73570 to be exploited?
CVE-2026-73570 can be exploited when the zimbra-snmp package is installed and SNMP notifications are enabled.
What should I do if I can't upgrade to resolve CVE-2026-73570?
If you cannot upgrade, it is recommended to disable the zimbra-snmp package and monitor your environment for any suspicious activity.