A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.
Metrics
Affected Vendors & Products
References
History
Thu, 13 Aug 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Remote Code Execution via SNMP Notification in Zimbra Collaboration Before 10.1.20 |
Thu, 13 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 13 Aug 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user. | |
| First Time appeared |
Zimbra
Zimbra collaboration |
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:2.3:a:zimbra:collaboration:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Zimbra
Zimbra collaboration |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-08-13T15:57:25.921Z
Reserved: 2026-08-12T21:44:20.945Z
Link: CVE-2026-73570
Updated: 2026-08-13T15:57:21.280Z
Status : Received
Published: 2026-08-13T16:19:06.003
Modified: 2026-08-13T16:19:06.003
Link: CVE-2026-73570
No data.
OpenCVE Enrichment
Updated: 2026-08-13T21:30:10Z