CVE-2026-33370

An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A stored cross-site scripting (XSS) vulnerability exists in the Zimbra Briefcase feature due to insufficient sanitization of specific uploaded file types. When a user opens a publicly shared Briefcase file containing malicious scripts, the embedded JavaScript executes in the context of the user's session. This allows an attacker to run arbitrary scripts, potentially leading to data exfiltration or other unauthorized actions on behalf of the victim user.
Configurations

Configuration 1 (hide)

cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:*

History

01 Apr 2026, 15:36

Type Values Removed Values Added
CPE cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:*
References () https://wiki.zimbra.com/wiki/Security_Center - () https://wiki.zimbra.com/wiki/Security_Center - Vendor Advisory, Release Notes
References () https://wiki.zimbra.com/wiki/Zimbra_Releases/10.1.16#Security_Fixes - () https://wiki.zimbra.com/wiki/Zimbra_Releases/10.1.16#Security_Fixes - Release Notes
References () https://wiki.zimbra.com/wiki/Zimbra_Responsible_Disclosure_Policy - () https://wiki.zimbra.com/wiki/Zimbra_Responsible_Disclosure_Policy - Product
References () https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories - () https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories - Vendor Advisory
First Time Synacor zimbra Collaboration Suite
Synacor
Summary
  • (es) Se descubrió un problema en Zimbra Collaboration (ZCS) 10.0 y 10.1. Existe una vulnerabilidad de cross-site scripting (XSS) almacenado en la función Zimbra Briefcase debido a una sanitización insuficiente de tipos de archivos subidos específicos. Cuando un usuario abre un archivo de Briefcase compartido públicamente que contiene scripts maliciosos, el JavaScript incrustado se ejecuta en el contexto de la sesión del usuario. Esto permite a un atacante ejecutar scripts arbitrarios, lo que podría llevar a la exfiltración de datos o a otras acciones no autorizadas en nombre del usuario víctima.

23 Mar 2026, 14:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
CWE CWE-79

20 Mar 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-20 14:16

Updated : 2026-04-01 15:36


NVD link : CVE-2026-33370

Mitre link : CVE-2026-33370

CVE.ORG link : CVE-2026-33370


JSON object : View

Products Affected

synacor

  • zimbra_collaboration_suite
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')