A policy-enforcement flaw in Zimbra Collaboration Suite...
Moderate severity
Unreviewed
Published
Oct 8, 2026
to the GitHub Advisory Database
•
Updated Oct 8, 2026
Description
Published by the National Vulnerability Database
Oct 8, 2026
Published to the GitHub Advisory Database
Oct 8, 2026
Last updated
Oct 8, 2026
A policy-enforcement flaw in Zimbra Collaboration Suite allows an authenticated user to bypass disabled mail forwarding by using a Sieve notify action to send copies of email content and headers to an arbitrary address.
References