CVE-2026-73571
LOW
NVD
CVSS Score
3.1
Severity
LOW
Published
Aug 13, 2026
Vendor
unknown
Description
An authorization bypass vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.17 due to improper authorization validation in delegated email sending functionality. An authenticated attacker can send specially crafted SOAP requests to impersonate another user and send emails without possessing the required delegation or send-as permissions. This occurs in the SaveDraftRequest SOAP handler.