CVE-2026-73575: CSRF
In Zimbra Collaboration (ZCS) before 10.1.17, a Cross-Site Request Forgery (CSRF) vulnerability exists in the Exchange Web Services (EWS) endpoint of Zimbra Collaboration (ZCS) due to insufficient validation of request content types. An attacker can exploit this vulnerability by causing an authenticated user to submit a crafted request, potentially allowing unauthorized actions to be performed on behalf of the victim.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-73575?
The severity of CVE-2026-73575 is classified as low, with a CVSS score of 3.1.
What type of vulnerability is CVE-2026-73575?
CVE-2026-73575 is a Cross-Site Request Forgery (CSRF) vulnerability.
How do I fix CVE-2026-73575?
To fix CVE-2026-73575, upgrade to Zimbra Collaboration (ZCS) version 10.1.17 or later.
How can attackers exploit CVE-2026-73575?
Attackers can exploit CVE-2026-73575 by crafting requests that bypass insufficient validation of content types in the EWS endpoint.
Is there any impact on data confidentiality due to CVE-2026-73575?
CVE-2026-73575 does not impact data confidentiality as it has no effect on data exposure.