Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 13 Aug 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Zimbra Briefcase Path Traversal Vulnerability Allowing Sensitive File Disclosure |
Thu, 13 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 13 Aug 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Zimbra Collaboration (ZCS) before 10.1.17, a path traversal vulnerability exists in the Zimbra Briefcase document editing functionality due to improper validation of the packages parameter. An authenticated attacker can exploit this vulnerability by supplying a crafted path traversal sequence, potentially allowing unauthorized disclosure of sensitive files within the web application directory. | |
| First Time appeared |
Zimbra
Zimbra collaboration |
|
| Weaknesses | CWE-24 | |
| CPEs | cpe:2.3:a:zimbra:collaboration:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Zimbra
Zimbra collaboration |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-08-13T15:58:09.171Z
Reserved: 2026-08-12T21:54:20.822Z
Link: CVE-2026-73573
Updated: 2026-08-13T15:58:03.541Z
Status : Received
Published: 2026-08-13T16:19:06.437
Modified: 2026-08-13T16:19:06.437
Link: CVE-2026-73573
No data.
OpenCVE Enrichment
Updated: 2026-08-13T18:45:04Z