PT-2026-71682 · Zimbra+1 · Collaboration+2
CVE-2026-73576
·
Published
2026-08-13
·
Updated
2026-08-28
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Zimbra Collaboration (ZCS) versions prior to 10.1.17
Description
A weak cryptographic key generation issue exists in the OnlyOffice integration. The
zimbraDocumentEditingJwtSecret is generated using an insecure random number generator, which leads to insufficient entropy. An attacker who obtains a JSON Web Token (JWT)—a compact, URL-safe means of representing claims to be transferred between two parties—signed with this secret may be able to recover the signing secret through offline brute-force, potentially allowing for JWT forgery.Recommendations
Update Zimbra Collaboration (ZCS) to version 10.1.17 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Collaboration
Zimbra
Zimbra Collaboration Suite