Zimbra Collaboration Suite <10.1.17 OnlyOffice JWT Key Entropy Weakness
CVE-2026-73576 Published on August 13, 2026
In Zimbra Collaboration (ZCS) before 10.1.17, weak cryptographic key generation vulnerability exists in the OnlyOffice integration. The zimbraDocumentEditingJwtSecret is generated using an insecure random number generator, resulting in insufficient entropy. An attacker who obtains a JWT signed with the generated secret may be able to recover the JWT signing secret through offline brute-force, potentially enabling JWT forgery.
Vulnerability Analysis
CVE-2026-73576 is exploitable with network access, and requires small amount of user privileges. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality, a high impact on integrity, and no impact on availability.
Weakness Type
Use of Predictable Algorithm in Random Number Generator
The device uses an algorithm that is predictable and generates a pseudo-random number.
Products Associated with CVE-2026-73576
Want to know whenever a new CVE is published for Zimbra Collaboration? stack.watch will email you.
Affected Versions
Zimbra Collaboration:- Before 10.1.17 is affected.