MEDIUM🇬🇧 English

CVE-2026-73576

CVSS 6.3v3.1pub. 2026-08-13upd. 2026-08-28

In Zimbra Collaboration (ZCS) before 10.1.17, weak cryptographic key generation vulnerability exists in the OnlyOffice integration. The zimbraDocumentEditingJwtSecret is generated using an insecure random number generator, resulting in insufficient entropy. An attacker who obtains a JWT signed with the generated secret may be able to recover the JWT signing secret through offline brute-force, potentially enabling JWT forgery.

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:N
  • Synacor Zimbra Collaboration Suite

    APP
    Synacor
    < 10.1.17
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Referencje

Powiązane podatności

CVE-2024-45519CRITICAL10.0⚠ KEVPL ✓ten sam produkt

RCE w usłudze postjournal Zimbra Collaboration Suite — command injection bez uwierzytelnienia

CVE-2023-34192CRITICAL9.0⚠ KEVPL ✓ten sam produkt

XSS umożliwiający RCE w Zimbra Collaboration Suite 8.8.15

CVE-2022-41352CRITICAL9.8⚠ KEVPL ✓ten sam produkt

Zimbra Collaboration – path traversal przez cpio umożliwia przejęcie kont

CVE-2022-37042CRITICAL9.8⚠ KEVPL ✓ten sam produkt

Zimbra ZCS: path traversal i RCE poprzez obejście uwierzytelnienia w mboximport

CVE-2020-7796CRITICAL9.8⚠ KEVPL ✓ten sam produkt

SSRF w Zimbra Collaboration Suite przez WebEx zimlet