Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories |
|
Thu, 08 Oct 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authorization flaw in Zimbra Collaboration Suite’s GrantRightsRequest allows an attacker with access to an authenticated account to grant another local account the loginAs right, creating persistent mailbox access and mail-sending authority that survives password changes and session expiry. | |
| Title | Zimbra Collaboration Suite GrantRightsRequest SOAP Handler Allows Self-Granting of Undocumented loginAs Mailbox Delegation Right | |
| Weaknesses | CWE-269 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: rapid7
Published:
Updated: 2026-10-08T16:25:37.442Z
Reserved: 2026-06-03T09:35:31.591Z
Link: CVE-2026-50054
No data.
Status : Received
Published: 2026-10-08T17:17:17.180
Modified: 2026-10-08T17:17:17.180
Link: CVE-2026-50054
No data.
OpenCVE Enrichment
No data.
-
CWE-269
Improper Privilege Management