{"id":"CVE-2026-93642","published":"2026-09-25T14:17:23.423","lastModified":"2026-09-29T21:29:07.663","description":"An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Modern recipient clicks Accept Share, allowing the attacker to access mailbox data and act as the victim.","cvssScore":9.3,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N","cwes":["CWE-79"],"vendors":[],"products":[],"references":[{"url":"https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"This vulnerability allows unauthenticated attackers to forge a share notification, leading to stored Cross-Site Scripting (XSS) and potential access to the victim's mailbox data.","exploitability":"Exploitation requires the victim to click on a forged share notification, making it somewhat dependent on user interaction.","blast_radius":"If exploited, attackers can access the victim's mailbox data and potentially act as the victim, leading to significant data exposure.","remediation":"Disable the Accept Share feature until a patch is available or upgrade to the latest version of Zimbra Modern.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["xss","web","auth-bypass","mail","zimbra"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-28T08:50:12.187Z"}}