Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-93647: Zimbra Classic web client lets crafted calendar sender steal data
CVE-2026-93647 · published 6 days ago
Summary
Anyone can send a specially crafted calendar invitation that contains hidden code in the From address. When a user opens that invitation in the Zimbra Classic web client, the code runs and can view the user’s mailbox and perform actions as if they were the user. Apply the latest Zimbra updates or patches to stop this behavior.
What to do
- Update zimbra zimbra collaboration suite (zcs) to version 10.1.21 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| zimbra | zimbra collaboration suite (zcs) | < 10.1.21 |
Original advisory text
Zimbra Collaboration Suite Classic Web Client Stored Cross-Site Scripting via Crafted Calendar COUNTER Message From Address
An unauthenticated calendar sender can place active markup in a COUNTER message's RFC From address. Selecting the message in Zimbra Classic triggers stored XSS, allowing the attacker to access mailbox data and act as the victim.
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Type
CWE-79Cross-site Scripting (XSS)
Timeline
Published25 Sep 2026
Updated29 Sep 2026
First seen25 Sep 2026
Track software like this
Free during beta