Medium severity6.5NVD Advisory· Published Oct 8, 2026· Updated Oct 8, 2026
CVE-2026-10631
CVE-2026-10631
Description
An authorization bypass in the EWS FindItem handler of Zimbra Collaboration Suite 10.1.0 through 10.1.19 allows an authenticated user with EWS enabled to read complete mailbox items, including raw MIME and attachments, from arbitrary local accounts without a share or delegation grant.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: 10.1.0 - 10.1.19
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.