← Back to search

CVE-2026-93647

9.3 CRITICAL

Published 2026-09-25 · Updated 2026-09-29

AI risk analysis

Summary
A cross-site scripting (XSS) vulnerability allows unauthenticated attackers to inject malicious content into a COUNTER message's RFC From address, leading to potential access to victim's mailbox data.
Exploitability
Exploitation is moderately difficult as it requires the attacker to craft a specific COUNTER message and ensure it is selected by the victim. Precondition is that the Zimbra Classic user must open the message.
Blast radius
If exploited, the attacker can access sensitive mailbox data and potentially impersonate the victim, leading to significant data breaches.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Disable the COUNTER message feature in Zimbra Classic until a patch is available.
xsswebmailunauth

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

An unauthenticated calendar sender can place active markup in a COUNTER message's RFC From address. Selecting the message in Zimbra Classic triggers stored XSS, allowing the attacker to access mailbox data and act as the victim.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N

Weaknesses

CWE-79

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.