CVE-2026-93647

Summary

An unauthenticated calendar sender can place active markup in a COUNTER message's RFC From address. Selecting the message in Zimbra Classic triggers stored XSS, allowing the attacker to access mailbox data and act as the victim.

Affected Software

VendorProductVersion RangeStatus
ZimbraZimbra Collaboration Suite (ZCS)0 < 10.1.21affected

Weaknesses

  • CWE-79: CWE-79 Improper neutralization of input during web page generation ('cross-site scripting')

References