{"id":"CVE-2026-93641","published":"2026-09-25T14:17:23.290","lastModified":"2026-09-29T21:29:07.663","description":"An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Classic recipient clicks Accept Share, allowing the attacker to access mailbox data and act as the victim.","cvssScore":9.3,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N","cwes":["CWE-79"],"vendors":[],"products":[],"references":[{"url":"https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"This flaw allows unauthenticated attackers to forge a share notification, leading to stored cross-site scripting (XSS) when a signed-in user clicks on it, granting the attacker access to the victim's mailbox data.","exploitability":"Exploitation is relatively straightforward as it requires only the forging of a share notification, which can be done with minimal effort.","blast_radius":"If exploited, the attacker can access the victim's mailbox data and potentially act as the victim, leading to significant data exposure and privacy breaches.","remediation":"Disable the Accept Share feature or restrict access to the feature to authenticated users only.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["xss","web","auth-bypass","mail","defensive"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-28T08:50:06.498Z"}}