← Vulnerability feed

Vulnerability record · CVE-2022-27925 · published 21 April 2022

CVE-2022-27925: Zimbra Collaboration mboximport ZIP path traversal allows arbitrary file upload

SSynacor · Zimbra Collaboration Suite

Zimbra Collaboration Suite 8.8.15 and 9.0 mboximport functionality accepts a ZIP archive and extracts files without properly validating paths, allowing directory traversal. An authenticated administrator can upload arbitrary files to the system, which can lead to code execution or full compromise of the mail server.

7.2 CVSS 3.1 High CISA KEV since 11 Aug 2022 Known ransomware use EPSS 99% · top 0.1% CWE-22 · Path traversal
7.2CVSS 3.1 base score, v2 6.5
99%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
9References, 2 tagged exploit
4 Aug 2026Last modified by NVD

Description

Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated user with administrator rights has the ability to upload arbitrary files to the system, leading to directory traversal.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityThe vulnerability is in CISA KEV with known ransomware use, has a very high EPSS score, and allows an authenticated administrator to achieve arbitrary file write and likely remote code execution.

What it is

Zimbra Collaboration Suite 8.8.15 and 9.0 mboximport functionality accepts a ZIP archive and extracts files without properly validating paths, allowing directory traversal. An authenticated administrator can upload arbitrary files to the system, which can lead to code execution or full compromise of the mail server.

Impact

An attacker with administrative rights can write files to arbitrary locations on the server, enabling web shell placement, configuration tampering, or remote code execution. This can result in complete compromise of the Zimbra host and access to mail data.

Attack surface

The flaw is reachable over the network via the mboximport feature, requiring authentication with administrator privileges and no user interaction. The CVSS vector confirms network access, low complexity, and high privileges required.

Exploitation

CVE-2022-27925 is listed in CISA KEV with known ransomware campaign use, and EPSS indicates a very high probability of exploitation. Public exploit references are available, confirming active exploitation in the wild.

What to do

  • Apply the vendor updates referenced in Zimbra Security Advisories and release notes (e.g., 9.0.0 P24) as soon as possible.
  • Restrict administrative access to the Zimbra administration console and mboximport functionality to trusted networks or IP allowlists.
  • Enforce strong authentication and monitor for unauthorized administrative account usage.
  • If patching is not immediately possible, consider disabling or restricting the mboximport feature until updates are applied.
  • Review and harden file upload and extraction paths to prevent traversal, following vendor guidance.

Detection

  • Monitor Zimbra server logs for mboximport requests, especially those containing ZIP archives with path traversal sequences (e.g., ../).
  • Alert on unexpected file creation or modification in web-accessible directories or system paths outside normal Zimbra data directories.
  • Hunt for known web shell indicators or suspicious files in Zimbra web directories following mboximport activity.
  • Correlate administrative login events with subsequent file upload or extraction activity for anomalous behavior.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2022-27925 to the Known Exploited Vulnerabilities catalog on 11 August 2022 as "Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 1 September 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-27925 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-45519Zimbra Collaboration postjournal service unauthenticated command executionThe postjournal service in Zimbra Collaboration Suite fails to properly neutralize input, allowing OS command injection. Because the service can be r…KEVEPSS 100%analysed9.8CVE-2022-41352Zimbra Collaboration amavis cpio path traversal arbitrary file uploadZimbra Collaboration Suite 8.8.15 and 9.0 allow an attacker to upload arbitrary files through amavis by abusing cpio archive extraction into the web-…KEVEPSS 95%analysed9.8CVE-2022-37042Zimbra Collaboration Suite mboximport auth bypass path traversal RCEZimbra Collaboration Suite 8.8.15 and 9.0 mboximport accepts a ZIP archive and extracts files without requiring an authtoken, allowing unauthenticate…KEVEPSS 92%analysed9.8CVE-2020-7796Zimbra Collaboration Suite WebEx zimlet SSRFZimbra Collaboration Suite before 8.8.15 Patch 7 is vulnerable to server-side request forgery when the WebEx zimlet is installed and its JSP is enabl…KEVEPSS 84%analysed9.8CVE-2019-9670Zimbra mailboxd Autodiscover XXE allows unauthenticated compromiseThe mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 parses XML in the Autodiscover servlet without restricting extern…KEVEPSS 100%analysed9.0CVE-2023-34192Zimbra ZCS autoSaveDraft XSS enables remote code executionZimbra Collaboration Suite 8.8.15 has a cross-site scripting flaw in the /h/autoSaveDraft function. A remote authenticated attacker can inject a craf…KEVEPSS 77%analysed8.9CVE-2026-73570Zimbra Collaboration SNMP notification OS command injectionZimbra Collaboration Suite before 10.1.20 contains an OS command injection flaw in SNMP notification processing when the optional zimbra-snmp package…KEVEPSS 12%analysed8.8CVE-2025-68645Zimbra Webmail Classic UI RestFilter local file inclusionZimbra Collaboration Suite 10.0 and 10.1 mishandle user-supplied parameters in the RestFilter servlet of the Webmail Classic UI, allowing local file …KEVEPSS 49%analysed

Source: NIST National Vulnerability Database (record CVE-2022-27925), CISA KEV, FIRST EPSS (scores of 2026-09-22). This page is refreshed as NVD updates the record.