Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories |
|
Thu, 08 Oct 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zimbra
Zimbra zimbra Collaboration Suite |
|
| Vendors & Products |
Zimbra
Zimbra zimbra Collaboration Suite |
Thu, 08 Oct 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authorization flaw in Zimbra Collaboration Suite’s GrantRightsRequest allows an attacker with access to an authenticated account to grant another local account the loginAs right, creating persistent mailbox access and mail-sending authority that survives password changes and session expiry. | |
| Title | Zimbra Collaboration Suite GrantRightsRequest SOAP Handler Allows Self-Granting of Undocumented loginAs Mailbox Delegation Right | |
| Weaknesses | CWE-269 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: rapid7
Published:
Updated: 2026-10-08T19:10:47.375Z
Reserved: 2026-06-03T09:35:31.591Z
Link: CVE-2026-50054
No data.
Status : Awaiting Analysis
Published: 2026-10-08T17:17:17.180
Modified: 2026-10-08T20:49:23.240
Link: CVE-2026-50054
No data.
OpenCVE Enrichment
Updated: 2026-10-08T18:30:07Z
-
CWE-269
Improper Privilege Management