CVE-2026-50054
EUVD-2026-9509708.10.2026, 17:17
An authorization flaw in Zimbra Collaboration Suite’s GrantRightsRequest allows an attacker with access to an authenticated account to grant another local account the loginAs right, creating persistent mailbox access and mail-sending authority that survives password changes and session expiry.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| zimbra | collaboration | 𝑥 < 10.1.20 | CNA |
Common Weakness Enumeration