The vulnerability exists due to an authorization validation loophole inside the mailbox delegation processing subsystem, allowing a delegated account profile to bypass boundary checks and perform actions outside its explicitly granted system scope.
https://www.securityweek.com/zimbra-update-patches-critical-vulnerabilities/