CVE-2026-50054
HIGH
NVD
CVSS Score
7.1
Severity
HIGH
Published
Oct 08, 2026
Vendor
unknown
Description
An authorization flaw in Zimbra Collaboration Suite’s GrantRightsRequest allows an attacker with access to an authenticated account to grant another local account the loginAs right, creating persistent mailbox access and mail-sending authority that survives password changes and session expiry.