Zimbra Classic Web Client XSS via Attachment Inline Preview (before 10.1.17)
CVE-2026-73572 Published on August 13, 2026
In Zimbra Collaboration (ZCS) before 10.1.17, a stored cross-site scripting (XSS) vulnerability exists in the Zimbra Classic Web Client due to insufficient sanitization of specific attachment content during inline preview. An attacker can send a crafted email containing a malicious attachment that, when previewed by a user, executes arbitrary JavaScript within the victim's browser session. Successful exploitation may allow an attacker to perform unauthorized actions on behalf of the victim user, potentially leading to data exfiltration or unauthorized access to sensitive information.
Vulnerability Analysis
CVE-2026-73572 is exploitable with network access, requires user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a small impact on confidentiality and integrity, and no impact on availability.
Weakness Type
What is a XSS Vulnerability?
The software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVE-2026-73572 has been classified to as a XSS vulnerability or weakness.
Products Associated with CVE-2026-73572
Want to know whenever a new CVE is published for Zimbra Collaboration? stack.watch will email you.
Affected Versions
Zimbra Collaboration:- Before 10.1.17 is affected.