External risk intelligence

Zimbra Classic Stored XSS via Forged Share Notification Allows Mailbox Access

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-93641

Zimbra is a web-based email and collaboration platform designed to be publicly accessible over the internet to support remote user access to mailboxes and shared resources.

Cross-site Scripting

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a critical vulnerability in Zimbra Classic that allows an unauthenticated attacker to potentially access mailbox data by tricking a user into clicking a malicious link. The vulnerability could enable an attacker to act on behalf of a victim, posing a significant risk to sensitive information.

  • Forged email can steal user mailbox data.
  • Impacts a widely used collaboration platform.
  • Confirm relevance and potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker can send a forged share notification to a Zimbra Classic user. When the recipient clicks on the "Accept Share" link within this notification, a stored cross-site scripting (XSS) vulnerability is triggered. This allows the attacker to potentially access the victim's mailbox data and perform actions on their behalf.

  • Unauthenticated sender can send malicious notification.
  • Recipient clicks "Accept Share" link.
  • Attacker accesses mailbox and acts as victim.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated sender can trick a signed-in Zimbra Classic user into clicking a malicious link within a forged share notification. This action could allow an attacker to access the victim's mailbox data and perform actions as that user.

  • Victim mailbox data
  • Malicious link in forged notification
  • Access mailbox data as victim

Operational Fix

Recommended remediation, mitigation, and detection steps

Action for this CVE likely falls to the Zimbra platform or infrastructure teams, with support from security operations for exposure analysis. The first practical step is to identify all deployed Zimbra Classic instances, confirm external reachability and business criticality, and then engage the accountable owner to plan remediation based on assessed risk.

  • Platform or Infrastructure teams own resolution.
  • Verify external reachability and business criticality.
  • Plan remediation based on assessed risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Zimbra Classic?

Zimbra Classic is a web-based email and collaboration platform. It serves as a central hub where users manage their professional communications, calendars, and shared resources through a browser-based interface, making it a common tool for organizational productivity and remote teamwork.

What does CWE-79 mean in CVE-2026-93641?

CWE-79 refers to Improper Neutralization of Input During Web Page Generation, commonly known as Stored Cross-Site Scripting (XSS). This means the application incorrectly saves malicious scripts from a user and later executes them in the browser of another user, potentially allowing an attacker to manipulate the page's content or steal information.

How is this vulnerability triggered?

The vulnerability is triggered when a signed-in user interacts with a forged share notification by clicking an 'Accept Share' link. It is important to note that the simple receipt of the notification is not enough; the active participation of the recipient, who must be logged into the platform, is required to execute the stored malicious script.

Do I need to worry about this if my Zimbra server is internal?

According to Halo Surface Signal, Zimbra is typically deployed to be publicly accessible to support remote work, which increases the likelihood of external reachability. If your instance is truly isolated from the internet, your risk profile may be lower, but you should verify if any external pathways exist that could allow an unauthenticated sender to deliver the forged notification to your users.

How should I respond to this threat?

Start by identifying every instance of Zimbra Classic running in your environment. Once you have a complete inventory, assess their reachability and business impact to prioritize them. Coordinate with your platform or infrastructure teams to review the official Zimbra security advisories and prepare to apply the necessary updates or configuration changes.

References