CVE-2026-33373 Details
Description
An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A Cross-Site Request Forgery (CSRF) vulnerability exists in Zimbra Web Client due to the issuance of authentication tokens without CSRF protection during certain account state transitions. Specifically, tokens generated after operations such as enabling two-factor authentication or changing a password may lack CSRF enforcement. While such a token is active, authenticated SOAP requests that trigger token generation or state changes can be performed without CSRF validation. An attacker could exploit this by inducing a victim to submit crafted requests, potentially allowing sensitive account actions such as disabling two-factor authentication. The issue is mitigated by ensuring CSRF protection is consistently enforced for all issued authentication tokens.
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Zimbra Collaboration Web Client, specifically in versions 10.0 and 10.1. This vulnerability arises from the issuance of authentication tokens without proper CSRF protection during certain account state transitions, such as enabling two-factor authentication or changing a password. While these tokens are active, authenticated SOAP requests can be made to trigger token generation or state changes without CSRF validation. An attacker could exploit this by convincing a victim to submit crafted requests, potentially allowing sensitive account actions like disabling two-factor authentication.
Users are advised to upgrade to Zimbra Collaboration versions 10.1.13 or 10.0.18, both of which include the necessary CSRF protections. Instructions for upgrading can be found on the Zimbra Releases page.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://wiki.zimbra.com/wiki/Security_Center | [email protected] | Release NotesVendor Advisory |
| https://wiki.zimbra.com/wiki/Zimbra_Releases/10.0.18#Security_Fixes | [email protected] | Release Notes |
| https://wiki.zimbra.com/wiki/Zimbra_Releases/10.1.13#Security_Fixes | [email protected] | Release Notes |
| https://wiki.zimbra.com/wiki/Zimbra_Responsible_Disclosure_Policy | [email protected] | Product |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-352 | Cross-Site Request Forgery (CSRF) | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| synacor zimbra collaboration suite | >= 10.0.0, < 10.0.18 >= 10.1.0, < 10.1.13 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 7, 2026 | Initial Analysis | [email protected] |
| Apr 1, 2026 | CVE Modified | CISA-ADP |
| Mar 30, 2026 | New CVE Received | [email protected] |