Junglewise Threat Intelligence

CVE-2020-7796: Synacor Zimbra Collaboration Suite SSRF in WebEx zimlet

CVE-2020-7796 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2026-02-17

Executive brief

Zimbra Collaboration Suite, a widely used enterprise email and collaboration platform, contains a critical security flaw in its WebEx integration component. An attacker can exploit this vulnerability to force the server to perform unauthorized requests, potentially leading to the theft of sensitive internal data or full system takeover. This vulnerability has been observed being used in active attacks.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability (CWE-918) exists in Synacor Zimbra Collaboration Suite (ZCS) versions prior to 8.8.15 Patch 7. The flaw is located within the WebEx zimlet and is exploitable when zimlet JSP is enabled. A remote, unauthenticated attacker can send specially crafted requests to the server, causing it to make outbound requests to arbitrary internal or external resources. This can be used to bypass network firewalls, access internal services, or exfiltrate sensitive information. This vulnerability is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Affected products

  • Synacor Zimbra Collaboration Suite (ZCS) Before 8.8.15 Patch 7

Timeline

  • 2020-02-18: disclosed: Initial NVD publication
  • 2020-02-18: patched: Fixed in 8.8.15 Patch 7
  • 2026-02-17: kev added: Added to CISA Known Exploited Vulnerabilities catalog

Related threats