Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 02 Apr 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | LDAP Injection in Zimbra Collaboration Mailbox SOAP Service |
Wed, 01 Apr 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Synacor
Synacor zimbra Collaboration Suite |
|
| CPEs | cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Synacor
Synacor zimbra Collaboration Suite |
Wed, 25 Mar 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | LDAP Injection in Zimbra Collaboration Mailbox SOAP Service |
Mon, 23 Mar 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-20 | |
| Metrics |
cvssV3_1
|
Fri, 20 Mar 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zimbra
Zimbra collaboration |
|
| Vendors & Products |
Zimbra
Zimbra collaboration |
Fri, 20 Mar 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Zimbra Collaboration (ZCS) 10.0 and 10.1 contains an LDAP injection vulnerability in the Mailbox SOAP service within a FolderAction operation. The application fails to properly sanitize user-supplied input before incorporating it into an LDAP search filter. An authenticated attacker can exploit this issue by sending a crafted SOAP request that manipulates the LDAP query, allowing retrieval of sensitive directory attributes. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-03-23T13:36:25.874Z
Reserved: 2026-03-19T00:00:00.000Z
Link: CVE-2026-33369
Updated: 2026-03-23T13:36:03.252Z
Status : Analyzed
Published: 2026-03-20T14:16:16.017
Modified: 2026-04-01T15:36:59.913
Link: CVE-2026-33369
No data.
OpenCVE Enrichment
Updated: 2026-04-02T07:59:41Z