Executive brief
Synacor Zimbra Collaboration Suite, a widely used enterprise email and collaboration platform, contains a critical security flaw in its classic web interface. An attacker can exploit this vulnerability to access sensitive internal files, potentially leading to the exposure of private data or system compromise. This vulnerability is currently being exploited in the wild, making immediate patching essential to protect corporate communications and operations.
Technical details
A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) versions 10.0 and 10.1. The flaw is rooted in the improper handling of user-supplied request parameters within the RestFilter servlet. An unauthenticated remote attacker can craft malicious requests to the /h/rest endpoint to manipulate internal request dispatching. This allows the inclusion and potentially the execution of arbitrary files located within the WebRoot directory. The vulnerability is tracked as CWE-98 and has been observed in active exploitation. Patches are available in ZCS versions 10.0.18 and 10.1.13.
Affected products
- Synacor Zimbra Collaboration Suite (ZCS) 10.0.0 to 10.0.17, 10.1.0 to 10.1.12
Timeline
- 2025-12-22: disclosed: Initial CVE publication
- 2026-01-22: kev added: Added to CISA Known Exploited Vulnerabilities catalog
- 2026-01-22: advisory: CISA advisory published