MEDIUM🇵🇱 Wersja polska

CVE-2026-73576

CVSS 6.3v3.1pub. 2026-08-13upd. 2026-08-28

In Zimbra Collaboration (ZCS) before 10.1.17, weak cryptographic key generation vulnerability exists in the OnlyOffice integration. The zimbraDocumentEditingJwtSecret is generated using an insecure random number generator, resulting in insufficient entropy. An attacker who obtains a JWT signed with the generated secret may be able to recover the JWT signing secret through offline brute-force, potentially enabling JWT forgery.

CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:N
  • Synacor Zimbra Collaboration Suite

    APP
    Synacor
    < 10.1.17
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-45519CRITICAL10.0⚠ KEVPL ✓same product

RCE w usłudze postjournal Zimbra Collaboration Suite — command injection bez uwierzytelnienia

CVE-2023-34192CRITICAL9.0⚠ KEVPL ✓same product

XSS umożliwiający RCE w Zimbra Collaboration Suite 8.8.15

CVE-2022-41352CRITICAL9.8⚠ KEVPL ✓same product

Zimbra Collaboration – path traversal przez cpio umożliwia przejęcie kont

CVE-2022-37042CRITICAL9.8⚠ KEVPL ✓same product

Zimbra ZCS: path traversal i RCE poprzez obejście uwierzytelnienia w mboximport

CVE-2020-7796CRITICAL9.8⚠ KEVPL ✓same product

SSRF w Zimbra Collaboration Suite przez WebEx zimlet