ctipilot.ch

CVE-2026-10631 — Zimbra: EWS extension access-control issue (fixed 10.1.20; RESERVED on NVD)

cve · CVE-2026-10631

Coverage timeline
1
first 2026-07-22 → last 2026-07-22
Peak priority
notable
1 notable
Sources cited
4
4 hosts
Sections touched
1
trending-vulnerabilities
Co-occurring entities
2
see Related entities below
ATT&CK techniques
3
pinned v19.1 · see below

Hunting pivots

ATT&CK techniques
Affected products
Zimbra Classic Web ClientZimbra Collaboration Suite

ATT&CK techniques

3 techniques observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.1 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-07-22/zimbra-10-1-20-snmp-command-injection-rce-plus-stored-xss · ATT&CK page ↗

Execution TA0002

T1059Command and Scripting Interpreter×1

Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of Unix Shell while Windows installations include the Windows Command Shell and PowerShell.

Evidence: 2026-07-22/zimbra-10-1-20-snmp-command-injection-rce-plus-stored-xss · ATT&CK page ↗

Collection TA0009

T1114.003Email Collection: Email Forwarding Rule×1

Adversaries may setup email forwarding rules to collect sensitive information. Adversaries may abuse email forwarding rules to monitor the activities of a victim, steal information, and further gain intelligence on the victim or the victim’s organization to use as part of further exploits or operations. Furthermore, email forwarding rules can allow adversaries to maintain persistent access to victim's emails even after compromised credentials are reset by administrators. Most email clients allow users to create inbox rules for various email functions, including forwarding to a different recipient. These rules may be created through a local email application, a web interface, or by command-line interface. Messages can be forwarded to internal or external recipients, and there are no restrictions limiting the extent of this rule. Administrators may also create forwarding rules for user accounts with the same considerations and outcomes.

Evidence: 2026-07-22/zimbra-10-1-20-snmp-command-injection-rce-plus-stored-xss · ATT&CK page ↗

Story timeline

  1. 2026-07-22Zimbra Collaboration Suite 10.1.20 — permanent fix for an SNMP command-injection RCE plus four stored-XSS bugs; NCSC-CH and BSI both flag the release
    trending-vulnerabilitiesZimbra ships 10.1.20 with the permanent fix for an SNMP command-injection RCE; NCSC-CH and BSI flag it for on-prem mail operators

Where this entity is cited

  • trending-vulnerabilities1

Source distribution

  • blog.zimbra.com1 (25%)
  • security-hub.ncsc.admin.ch1 (25%)
  • thehackernews.com1 (25%)
  • wid.cert-bund.de1 (25%)

Co-occurring entities

Derived — referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about CVE-2026-10631 — Zimbra: EWS extension access-control issue (fixed 10.1.20; RESERVED on NVD) (1)

2026-07-22 · view entry permalink →

NOTABLECVE-2026-50055 +2NATOA2

Zimbra Collaboration Suite 10.1.20 — permanent fix for an SNMP command-injection RCE plus four stored-XSS bugs; NCSC-CH and BSI both flag the release

Zimbra shipped Collaboration Suite (ZCS) 10.1.20 on 2026-07-20, fixing nine security issues; NCSC-CH and BSI CERT-Bund both flagged the release on 2026-07-21 (NCSC-CH, 2026-07-21; BSI CERT-Bund, 2026-07-21). The headline flaw is a command-injection vulnerability in Zimbra's SNMP monitoring component, exploitable when SNMP notifications are enabled, that lets an attacker execute arbitrary OS commands on the mail server; Zimbra describes 10.1.20 as the permanent fix for a vulnerability it first disclosed in a 26 June 2026 advisory and has withheld a CVE identifier and technical specifics "in line with industry best practices" pending wider patch adoption (Zimbra, 2026-07-20; The Hacker News, 2026-07-21). Four stored cross-site-scripting bugs in the Classic Web Client round out the un-CVE'd issues: malicious attachment filenames, crafted fields, and rendered attachments can each trigger script execution inside a victim's authenticated webmail session.

Three issues received CVE identifiers, listed in BSI's advisory: CVE-2026-50055, CVE-2026-10631 and CVE-2026-50054 — all three currently RESERVED on NVD/MITRE. The Hacker News maps CVE-2026-50055 to the mail-forwarding restriction bypass (letting an authenticated attacker exfiltrate mail even where forwarding restrictions are enforced) (The Hacker News, 2026-07-21); the other two correspond to the release's EWS-extension access-control and mailbox-delegation authorization fixes described in Zimbra's own advisory, but the cited sources do not state which CVE maps to which issue. The release also fixes an SSRF in Zimbra's Nextcloud integration. This is the second Zimbra security release inside two weeks, following ZCS 10.1.19's 10 July fix for a separate Classic Web Client crafted-email code-execution bug.

A command injection vulnerability in the SNMP monitoring component when SNMP notifications are enabled. (Permanent fix for the vulnerability disclosed in our security advisory on 26th June 2026)

A mail forwarding restriction bypass that could allow authenticated users to exfiltrate email despite mail forwarding restrictions being enabled.

Zimbra / Synacor 2026-07-20
vulnerability22 Jul 04:34Zmulti-sourceOpen finding ↗