CVE-2026-50054: Zimbra Collaboration Suite
High severity, CVSS 7.1. EPSS: 0.2% chance of exploitation in the next 30 days.
An authorization flaw in Zimbra Collaboration Suite’s GrantRightsRequest allows an attacker with access to an authenticated account to grant another local account the loginAs right, creating persistent mailbox access and mail-sending authority that survives password changes and session expiry.
Affected products
- Zimbra Zimbra Collaboration Suite: before 10.1.20 (fixed in 10.1.20)
Published 2026-10-08. Last modified 2026-10-08.