Zimbra Collaboration LDAP Injection Vulnerability in Mailbox SOAP Service

Vulnerability

An LDAP injection vulnerability has been identified in the Mailbox SOAP service of Zimbra Collaboration (ZCS) versions 10.0 and 10.1. This vulnerability occurs within the FolderAction operation, where the application fails to properly sanitize user-supplied input before it is incorporated into an LDAP search filter. As a result, an authenticated attacker can exploit this issue by sending a crafted SOAP request that manipulates the LDAP query, potentially leading to the retrieval of sensitive directory attributes.

Impact

Exploitation of this vulnerability allows for unauthorized manipulation of LDAP queries, which could result in the disclosure of sensitive directory information.

Remediation

Users can upgrade to ZCS versions 10.1.13 or 10.0.18, both of which include the necessary security fix. Instructions for upgrading can be found on the Zimbra Releases page.

Added: Mar 20, 2026, 2:21 PM
Updated: Mar 20, 2026, 2:21 PM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
2.5
exploitability
5.4
remediation
7.7
relevance
4.2
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.