CVE-2026-73576 Details
Description
In Zimbra Collaboration (ZCS) before 10.1.17, weak cryptographic key generation vulnerability exists in the OnlyOffice integration. The zimbraDocumentEditingJwtSecret is generated using an insecure random number generator, resulting in insufficient entropy. An attacker who obtains a JWT signed with the generated secret may be able to recover the JWT signing secret through offline brute-force, potentially enabling JWT forgery.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://wiki.zimbra.com/wiki/Zimbra_Responsible_Disclosure_Policy | [email protected] | Vendor Advisory |
| https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1241 | Use of Predictable Algorithm in Random Number Generator | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| synacor zimbra collaboration suite | < 10.1.17 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 28, 2026 | Initial Analysis | [email protected] |
| Aug 13, 2026 | New CVE Received | [email protected] |
| Aug 13, 2026 | CVE Modified | CISA-ADP |