External risk intelligence

Zimbra Classic Stored Cross-Site Scripting Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-93647

The vulnerability affects a web-based email client (Zimbra Classic). Such applications are commonly deployed as internet-facing services, as they provide remote access to mailbox data for users.

Cross-site Scripting

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability involves the Zimbra Classic email client, where an attacker could potentially insert malicious code into calendar messages. If a user selects such a message, the attacker might gain unauthorized access to mailbox data and perform actions on behalf of the user. The main concern is confirming if this specific technology is in use and exposed.

  • Malicious code in calendar messages can access mail.
  • Affects a widely used email client, Zimbra Classic.
  • Confirm relevance and exposure to users.

Attack Path

How an attacker could exploit the issue

An attacker can send a specially crafted calendar invitation with malicious code hidden in the sender's address. When a user opens this invitation in Zimbra Classic, the malicious code executes, potentially leading to the theft of sensitive mailbox information or unauthorized actions taken on behalf of the victim.

  • Requires no authentication to send.
  • Triggers when a message is selected.
  • Allows mailbox data access.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to inject malicious code into calendar messages. When a victim views such a message in Zimbra Classic, this code could execute, potentially granting the attacker access to the victim's mailbox data and enabling them to perform actions as that user.

  • Mailbox data could be accessed.
  • Via specially crafted calendar messages.
  • Unauthorized access to user accounts.

Operational Fix

Recommended remediation, mitigation, and detection steps

The real-world ownership of this vulnerability likely falls to teams managing the Zimbra Classic email platform, potentially including application owners, infrastructure, or platform teams, with coordination from network and security teams. The initial practical move is to identify all Zimbra Classic instances, confirm their exposure and business criticality, and then locate the accountable owner for remediation planning.

  • Identify Zimbra Classic deployment scope.
  • Verify external reachability and criticality.
  • Plan remediation with asset owners.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Zimbra Classic?

Zimbra Classic is a web-based email and collaboration platform designed for managing communications, calendars, and organizational contacts. It serves as a centralized hub where users interact with their mailboxes and schedule events through a web browser, making it a critical component for managing enterprise or community correspondence.

What does CVE-2026-93647 mean by stored XSS?

This vulnerability is classified as Improper Neutralization of Input During Web Page Generation, or CWE-79. In this context, it means the application fails to properly sanitize the sender's address field in calendar messages. Because the malicious markup is stored by the server and rendered when a victim views the message, the browser treats the attacker's input as legitimate code, granting unauthorized access to the victim's session.

How is the vulnerability triggered?

An attacker initiates the process by sending a calendar invitation containing specially crafted markup within the 'From' address field. The vulnerability does not trigger if the message remains unopened; the malicious code only executes when the recipient actively selects or opens the infected message within the Zimbra Classic interface.

Is my Zimbra Classic instance at risk?

Halo Surface Signal indicates that Zimbra Classic is frequently deployed as an internet-facing service to support remote user access to mailboxes. If your instance is reachable from the public internet, it falls into a higher risk category, as external attackers can deliver these calendar messages directly to your users without prior authentication.

What should I do first to address this?

Begin by auditing your environment to locate all active deployments of Zimbra Classic. Once identified, evaluate whether these instances are accessible to the public or restricted to internal networks. Document the business criticality of each instance and coordinate with the respective system owners to prepare for security updates or configuration changes.

References