The vulnerability exists due to an access control verification defect within the Exchange Web Services extension component, which enables authenticated software users to exceed their intended operational privileges and access restricted server management modules.
https://www.securityweek.com/zimbra-update-patches-critical-vulnerabilities/