CVE-2026-93641: Zimbra Collaboration Suite Classic Web Client Stored Cross-Site Scripting via Forged Share Invitation
Published Sep 25, 2026
·Updated
An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Classic recipient clicks Accept Share, allowing the attacker to access mailbox data and act as the victim.
Affected Software
1 affected component
Zimbra Zimbra Collaboration Suite Classic Web Client
Event History
Sep 25, 2026
CVE Published
via MITRE·01:55 PM
Data Sourced
via MITRE·01:55 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who is exposed to this issue?
Users of the Zimbra Collaboration Suite Classic Web Client are exposed if they are signed in and click Accept Share on a forged share notification. The attacker does not need to authenticate.
2
What does an attacker need to exploit this vulnerability?
The attacker needs to send a forged share notification and persuade a signed-in Classic Web Client recipient to click Accept Share. No attacker privileges are required, but user interaction is required.
3
What could happen after successful exploitation?
The stored cross-site scripting can allow the attacker to access the victim's mailbox data and perform actions as the victim.