CVE-2026-33370 Details
Description
An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A stored cross-site scripting (XSS) vulnerability exists in the Zimbra Briefcase feature due to insufficient sanitization of specific uploaded file types. When a user opens a publicly shared Briefcase file containing malicious scripts, the embedded JavaScript executes in the context of the user's session. This allows an attacker to run arbitrary scripts, potentially leading to data exfiltration or other unauthorized actions on behalf of the victim user.
A stored cross-site scripting vulnerability has been identified in the Zimbra Collaboration (ZCS) versions 10.0 and 10.1. This vulnerability arises in the Briefcase feature due to inadequate sanitization of certain uploaded file types. When a user accesses a publicly shared Briefcase file that contains malicious scripts, the embedded JavaScript executes within the user's session context. This exploitation allows an attacker to execute arbitrary scripts, potentially leading to unauthorized actions or data exfiltration on behalf of the affected user.
Users can upgrade to ZCS versions 10.1.16, 10.0.18, or 8.8.15 Patch 47, all of which include the necessary fix for this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://wiki.zimbra.com/wiki/Security_Center | [email protected] | Release NotesVendor Advisory |
| https://wiki.zimbra.com/wiki/Zimbra_Releases/10.1.16#Security_Fixes | [email protected] | Release Notes |
| https://wiki.zimbra.com/wiki/Zimbra_Responsible_Disclosure_Policy | [email protected] | Product |
| https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| synacor zimbra collaboration suite | >= 10.0.0, < 10.1.16 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 1, 2026 | Initial Analysis | [email protected] |
| Mar 23, 2026 | CVE Modified | CISA-ADP |
| Mar 20, 2026 | New CVE Received | [email protected] |