CVE-2026-73573: Path Traversal
In Zimbra Collaboration (ZCS) before 10.1.17, a path traversal vulnerability exists in the Zimbra Briefcase document editing functionality due to improper validation of the packages parameter. An authenticated attacker can exploit this vulnerability by supplying a crafted path traversal sequence, potentially allowing unauthorized disclosure of sensitive files within the web application directory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-73573?
The severity of CVE-2026-73573 is classified as low with a score of 3.1.
How do I fix CVE-2026-73573?
To fix CVE-2026-73573, upgrade Zimbra Collaboration to version 10.1.17 or later.
What kind of vulnerability is CVE-2026-73573?
CVE-2026-73573 is a path traversal vulnerability found in the Zimbra Briefcase document editing functionality.
Who can exploit CVE-2026-73573?
An authenticated attacker can exploit CVE-2026-73573 by providing a crafted path traversal sequence.
In which product is CVE-2026-73573 found?
CVE-2026-73573 is found in Zimbra Collaboration (ZCS) versions prior to 10.1.17.