PT-2026-71682 · Zimbra+1 · Collaboration+2

CVE-2026-73576

·

Published

2026-08-13

·

Updated

2026-08-28

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Zimbra Collaboration (ZCS) versions prior to 10.1.17
Description A weak cryptographic key generation issue exists in the OnlyOffice integration. The zimbraDocumentEditingJwtSecret is generated using an insecure random number generator, which leads to insufficient entropy. An attacker who obtains a JSON Web Token (JWT)—a compact, URL-safe means of representing claims to be transferred between two parties—signed with this secret may be able to recover the signing secret through offline brute-force, potentially allowing for JWT forgery.
Recommendations Update Zimbra Collaboration (ZCS) to version 10.1.17 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73576

Affected Products

Collaboration
Zimbra
Zimbra Collaboration Suite