CVE-2026-33369

Zimbra Collaboration (ZCS) 10.0 and 10.1 contains an LDAP injection vulnerability in the Mailbox SOAP service within a FolderAction operation. The application fails to properly sanitize user-supplied input before incorporating it into an LDAP search filter. An authenticated attacker can exploit this issue by sending a crafted SOAP request that manipulates the LDAP query, allowing retrieval of sensitive directory attributes.
Configurations

Configuration 1 (hide)

cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:*

History

01 Apr 2026, 15:36

Type Values Removed Values Added
First Time Synacor zimbra Collaboration Suite
Synacor
CPE cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:*
References () https://wiki.zimbra.com/wiki/Security_Center - () https://wiki.zimbra.com/wiki/Security_Center - Vendor Advisory, Release Notes
References () https://wiki.zimbra.com/wiki/Zimbra_Releases/10.1.16#Security_Fixes - () https://wiki.zimbra.com/wiki/Zimbra_Releases/10.1.16#Security_Fixes - Release Notes
References () https://wiki.zimbra.com/wiki/Zimbra_Responsible_Disclosure_Policy - () https://wiki.zimbra.com/wiki/Zimbra_Responsible_Disclosure_Policy - Product
References () https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories - () https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories - Vendor Advisory
Summary
  • (es) Zimbra Collaboration (ZCS) 10.0 y 10.1 contiene una vulnerabilidad de inyección LDAP en el servicio SOAP de Mailbox dentro de una operación FolderAction. La aplicación no logra sanear adecuadamente la entrada proporcionada por el usuario antes de incorporarla a un filtro de búsqueda LDAP. Un atacante autenticado puede explotar este problema enviando una solicitud SOAP manipulada que manipula la consulta LDAP, permitiendo la recuperación de atributos de directorio sensibles.

23 Mar 2026, 14:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.3
CWE CWE-20

20 Mar 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-20 14:16

Updated : 2026-04-01 15:36


NVD link : CVE-2026-33369

Mitre link : CVE-2026-33369

CVE.ORG link : CVE-2026-33369


JSON object : View

Products Affected

synacor

  • zimbra_collaboration_suite
CWE
CWE-20

Improper Input Validation