Zimbra Collaboration SNMP command injection enables unauthenticated remote code execution

What is CVE-2026-73570?

CVE-2026-73570 is a vulnerability classified as Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), affecting Collaboration (affected versions: < 10.1.20). This vulnerability is rated High, with a CVSS score of 8.9. This vulnerability has been observed being exploited in the wild.

Verify to continue the analysis

A short verification protects the vulnerability source and prevents automated AI abuse.

Overview

Original source data

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.

Affected products and scope

  • Affected product: Zimbra Collaboration, also called ZCS, from Zimbra.
  • Structured affected range: versions before 10.1.20, represented as 0 < 10.1.20.
  • Configuration condition: the optional zimbra-snmp package must be installed and SNMP notifications must be enabled. CERT Polska specifically identifies the snmp_notify parameter and a running swatchdog service, which it describes as enabled by default.
  • The normalized product entry has default status unaffected, but installations meeting the conditions above are affected.
  • The vendor security advisory lists 10.1.20 as the fix release. The supplied evidence does not confirm separate fixed boundaries for parallel or older release branches.

Technical details

The vulnerability is in Zimbra Collaboration's SNMP notification processing. Untrusted attacker-controlled input is not properly sanitized and can be supplied through specially crafted SMTP requests. The recorded conditions include installation of the optional zimbra-snmp package, enabled SNMP notifications through snmp_notify, and a running swatchdog service. The attack is network reachable, requires no authentication or user interaction, and the normalized record characterizes attack complexity as high. Successful exploitation may execute operating system commands with the privileges of the zimbra user. The available evidence does not identify the exact vulnerable function or code path responsible for the sanitization failure.

Exploitability

The vulnerability is remotely reachable through SMTP requests. Exploitation does not require authentication or user interaction, while the normalized record characterizes attack complexity as high. The relevant deployment conditions are the installed zimbra-snmp package, enabled SNMP notifications, and a running swatchdog service. The record states that the vulnerability is known exploited and has a public exploit; CERT Polska also reports an ongoing campaign exploiting it. The available evidence does not name a specific victim, campaign, or complete exploit payload.

Technical impact

The primary technical outcome is execution of arbitrary operating system commands with the privileges of the zimbra user. Because the attack requires no authentication and can begin with a network SMTP request, a Zimbra server with the vulnerable configuration may be affected before the attacker obtains a valid account. The zimbra account may access or modify some data and service components, but the available evidence does not establish administrative or root access. Exploitation could lead to unauthorized access, data modification, or service disruption, with the actual scope determined by deployment permissions and configuration.

Business impact

Successful exploitation can provide operating system command execution under the zimbra account, potentially affecting the confidentiality, integrity, or availability of data and services accessible to that account. The practical impact depends on the account's permissions, the server configuration, and the degree of system isolation. An attacker may be able to modify files or service-related data writable by zimbra, access readable data, or disrupt Zimbra services. The evidence confirms exploitation activity but does not establish that a particular organization suffered a compromise or data loss.

Remediation

  1. Upgrade affected installations to the vendor-listed fixed release 10.1.20.
  2. After updating, verify the actual version on each server and recheck the status of zimbra-snmp, the snmp_notify setting, and the swatchdog service.
  3. If an immediate update is not possible, identify servers that can receive SMTP requests from untrusted networks and reduce that exposure where operationally feasible. This is temporary risk reduction, not a confirmed fix.
  4. Because the vulnerability is being exploited, review the logs and files described in the detection steps. If suspicious activity is found, preserve evidence and start incident response procedures.

Detection

  • Inventory Zimbra Collaboration versions on all servers and compare them with the affected range in the record.
  • Determine whether the optional zimbra-snmp package is installed.
  • Check the snmp_notify configuration to determine whether SNMP notifications are enabled, and confirm whether the swatchdog service is running.
  • Review /var/log/zimbra.log for the entries identified by CERT Polska:
  • Service status change: <szkodliwy ładunek> changed from stopped to running
  • Service status change: <szkodliwy ładunek> changed from running to stopped
  • Check for files created by the zimbra user during the last 30 days in /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/, and /tmp/.
  • These checks are recommended for the reported exploitation activity. The absence of suspicious logs or files does not prove that a system is safe; preserve evidence and investigate if anomalous activity is found.
Sources (7)
Learn more

Run an in-depth assessment with complete web risk management

CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.

Explore CyStack VulnScan
CyStack VulnScan dashboard