CVE-2026-93647: Zimbra Collaboration Suite Classic Web Client Stored Cross-Site Scripting via Crafted Calendar COUNTER Message From Address
Published Sep 25, 2026
·Updated
An unauthenticated calendar sender can place active markup in a COUNTER message's RFC From address. Selecting the message in Zimbra Classic triggers stored XSS, allowing the attacker to access mailbox data and act as the victim.
Affected Software
1 affected component
Zimbra Collaboration Suite Classic Web Client
Event History
Sep 25, 2026
CVE Published
via MITRE·01:58 PM
Data Sourced
via MITRE·01:58 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Does an attacker need a Zimbra account or other privileges to exploit this issue?
No. The issue can be triggered by an unauthenticated calendar sender using a crafted COUNTER message.
2
What must the recipient do for the payload to execute?
The victim must select the malicious calendar message in the Zimbra Classic Web Client.
3
What can an attacker do after successful exploitation?
The stored XSS can allow the attacker to access the victim's mailbox data and perform actions as the victim.