CVE-2026-33368

Source
https://cve.org/CVERecord?id=CVE-2026-33368
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-33368.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-33368
Published
2026-03-20T00:00:00Z
Modified
2026-07-15T01:49:11.039689735Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

Zimbra Collaboration Suite (ZCS) 10.0 and 10.1 contains a reflected cross-site scripting (XSS) vulnerability in the Classic Webmail REST interface (/h/rest). The application fails to properly sanitize user-supplied input, allowing an unauthenticated attacker to inject malicious JavaScript into a crafted URL. When a victim user accesses the link, the injected script executes in the context of the Zimbra webmail application, which could allow the attacker to perform actions on behalf of the victim.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/33xxx/CVE-2026-33368.json",
    "cna_assigner": "mitre"
}
References

Affected packages

Git / github.com/zimbra/zm-build

Affected ranges

Type
GIT
Repo
https://github.com/zimbra/zm-build
Events
Database specific
{
    "cpe": "cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:*",
    "source": "CPE_RANGE",
    "extracted_events": [
        {
            "introduced": "10.0.0"
        },
        {
            "fixed": "10.1.16"
        }
    ]
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-33368.json"

Git / github.com/zimbra/zm-zcs-lib

Affected ranges

Type
GIT
Repo
https://github.com/zimbra/zm-zcs-lib
Events
Database specific
{
    "cpe": "cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:*",
    "source": "CPE_RANGE",
    "extracted_events": [
        {
            "introduced": "10.0.0"
        },
        {
            "fixed": "10.1.16"
        }
    ]
}

Affected versions

10.*
10.0.0-GA
10.1.0
10.1.1
10.1.13
10.1.14
10.1.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-33368.json"