Back to database
Soon71High7.1VulnerabilityCVE-2026-50054No patch link observed

CVE-2026-50054 — An authorization flaw in Zimbra Collaboration Suite’s GrantRightsRequest allows an attacker with access to an authenticated account to grant anothe…

Published Oct 8, 2026, 05:17 PM UTCIngested 4h agoSource NVD(cve-db)CVE-2026-50054

Description

An authorization flaw in Zimbra Collaboration Suite’s GrantRightsRequest allows an attacker with access to an authenticated account to grant another local account the loginAs right, creating persistent mailbox access and mail-sending authority that survives password changes and session expiry.

CVSS v3.1 base metrics

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
7.1

High severity

Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.

AV

Network

Attack Vector

AC

Low

Attack Complexity

PR

Low

Privileges Required

UI

None

User Interaction

S

Unchanged

Scope

C

High

Confidentiality

I

Low

Integrity

A

None

Availability