CVE-2026-93642: Zimbra Collaboration Suite Modern Web Client Stored Cross-Site Scripting via Forged Share Invitation
Published Sep 25, 2026
·Updated
An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Modern recipient clicks Accept Share, allowing the attacker to access mailbox data and act as the victim.
Affected Software
1 affected component
Zimbra Zimbra Collaboration Suite Modern Web Client
Event History
Sep 25, 2026
CVE Published
via MITRE·01:56 PM
Data Sourced
via MITRE·01:56 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who is exposed to this issue?
Signed-in users of the Zimbra Modern Web Client are exposed if they receive a forged share notification and click Accept Share. The sender does not need to be authenticated.
2
What does an attacker need to do to exploit it?
The attacker needs to send a forged share notification and persuade a signed-in recipient to click Accept Share. No attacker privileges are required, but user interaction is required.
3
What can an attacker do after successful exploitation?
Successful exploitation allows stored cross-site scripting in the victim's Modern Web Client session. The attacker can access mailbox data and act as the victim.