Zimbra Collaboration Server 10.1.x < 10.1.20 Multiple Vulnerabilities

high Nessus Plugin ID 329328

Synopsis

The remote web server contains a web application that is affected by multiple vulnerabilities.

Description

According to its self-reported version number, Zimbra Collaboration Server is affected by multiple vulnerabilities, including:

- A remote code execution vulnerability exists when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user. (CVE-2026-73570)

- A security issue in the EWS extension related to access controls. (CVE-2026-10631)

- An authorization issue in mailbox delegation. (CVE-2026-50054)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade to version 10.1.20 or later.

See Also

https://wiki.zimbra.com/wiki/Zimbra_Releases/10.1.20

https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories

Plugin Details

Severity: High

ID: 329328

File Name: zimbra_10_1_20.nasl

Version: 1.4

Type: Combined

Agent: unix

Family: CGI abuses

Published: 7/24/2026

Updated: 8/27/2026

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Critical

Score: 9.3

Percentile: 99.81

CVSS v2

Risk Factor: High

Base Score: 7.3

Temporal Score: 6

Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:P

CVSS Score Source: CVE-2026-73570

CVSS v3

Risk Factor: High

Base Score: 8.9

Temporal Score: 8.3

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L

Temporal Vector: CVSS:3.0/E:F/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:zimbra:collaboration_suite

Required KB Items: installed_sw/zimbra_zcs

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 7/20/2026

Vulnerability Publication Date: 7/20/2026

Reference Information

CVE: CVE-2026-10631, CVE-2026-50054, CVE-2026-50055, CVE-2026-73570

CWE: 78

IAVA: 2026-A-0761