← Vulnerability feed

Vulnerability record · CVE-2022-41352 · published 26 September 2022

CVE-2022-41352: Zimbra Collaboration amavis cpio path traversal arbitrary file upload

SSynacor · Zimbra Collaboration Suite

Zimbra Collaboration Suite 8.8.15 and 9.0 allow an attacker to upload arbitrary files through amavis by abusing cpio archive extraction into the web-accessible /opt/zimbra/jetty/webapps/zimbra/public directory. Because the extracted files land under a served path, the flaw enables code or content placement that can lead to access to other user accounts. It is a critical, remotely reachable flaw with no authentication or user interaction required.

9.8 CVSS 3.1 Critical CISA KEV since 20 Oct 2022 Known ransomware use EPSS 95% · top 0.1% CWE-22 · Path traversal
9.8CVSS 3.1 base score
95%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
11References, 2 tagged exploit
10 Sep 2026Last modified by NVD

Description

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavis via a cpio loophole (extraction to /opt/zimbra/jetty/webapps/zimbra/public) that can lead to incorrect access to any other user accounts. Zimbra recommends pax over cpio. Also, pax is in the prerequisites of Zimbra on Ubuntu; however, pax is no longer part of a default Red Hat installation after RHEL 6 (or CentOS 6). Once pax is installed, amavis automatically prefers it over cpio.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityUnauthenticated network-exploitable file upload leading to code execution, listed in KEV with known ransomware use and near-maximum EPSS.

What it is

Zimbra Collaboration Suite 8.8.15 and 9.0 allow an attacker to upload arbitrary files through amavis by abusing cpio archive extraction into the web-accessible /opt/zimbra/jetty/webapps/zimbra/public directory. Because the extracted files land under a served path, the flaw enables code or content placement that can lead to access to other user accounts. It is a critical, remotely reachable flaw with no authentication or user interaction required.

Impact

An unauthenticated attacker can write arbitrary files into a web-served directory, which can lead to remote code execution and compromise of the mail server, including access to other users' accounts.

Attack surface

Reached over the network through the amavis mail-processing path that handles inbound mail attachments; the CVSS vector shows no privileges and no user interaction required.

Exploitation

CVE-2022-41352 is in CISA's Known Exploited Vulnerabilities catalog with known ransomware campaign use, and EPSS gives a 30-day probability of 0.95478 (99.867th percentile); public exploit code is referenced.

What to do

  • Apply the vendor patch per Zimbra security advisories and Security Center guidance.
  • Install pax so amavis prefers it over cpio, as Zimbra recommends, especially on Red Hat/CentOS systems where pax is absent after RHEL/CentOS 6.
  • If patching is delayed, restrict or disable amavis handling of untrusted archive attachments until pax is in place.
  • Verify the web-served public directory does not contain unexpected files and monitor it for new writes.
  • Treat this as an emergency change given KEV listing and ransomware use.

Detection

  • Monitor /opt/zimbra/jetty/webapps/zimbra/public for unexpected new or modified files.
  • Alert on cpio extraction activity by amavis and on archive attachments processed without pax present.
  • Hunt for web requests to newly written files under the public web path.
  • Review mail logs for suspicious archive attachments routed through amavis around the time of file creation.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2022-41352 to the Known Exploited Vulnerabilities catalog on 20 October 2022 as "Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 10 November 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-41352 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-45519Zimbra Collaboration postjournal service unauthenticated command executionThe postjournal service in Zimbra Collaboration Suite fails to properly neutralize input, allowing OS command injection. Because the service can be r…KEVEPSS 100%analysed9.8CVE-2022-37042Zimbra Collaboration Suite mboximport auth bypass path traversal RCEZimbra Collaboration Suite 8.8.15 and 9.0 mboximport accepts a ZIP archive and extracts files without requiring an authtoken, allowing unauthenticate…KEVEPSS 92%analysed9.8CVE-2020-7796Zimbra Collaboration Suite WebEx zimlet SSRFZimbra Collaboration Suite before 8.8.15 Patch 7 is vulnerable to server-side request forgery when the WebEx zimlet is installed and its JSP is enabl…KEVEPSS 84%analysed9.8CVE-2019-9670Zimbra mailboxd Autodiscover XXE allows unauthenticated compromiseThe mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 parses XML in the Autodiscover servlet without restricting extern…KEVEPSS 100%analysed9.0CVE-2023-34192Zimbra ZCS autoSaveDraft XSS enables remote code executionZimbra Collaboration Suite 8.8.15 has a cross-site scripting flaw in the /h/autoSaveDraft function. A remote authenticated attacker can inject a craf…KEVEPSS 77%analysed8.9CVE-2026-73570Zimbra Collaboration SNMP notification OS command injectionZimbra Collaboration Suite before 10.1.20 contains an OS command injection flaw in SNMP notification processing when the optional zimbra-snmp package…KEVEPSS 12%analysed8.8CVE-2025-68645Zimbra Webmail Classic UI RestFilter local file inclusionZimbra Collaboration Suite 10.0 and 10.1 mishandle user-supplied parameters in the RestFilter servlet of the Webmail Classic UI, allowing local file …KEVEPSS 49%analysed7.5CVE-2022-27924Zimbra Collaboration memcache command injection via unauthenticated requestZimbra Collaboration Suite 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instance. The inje…KEVEPSS 85%analysed

Source: NIST National Vulnerability Database (record CVE-2022-41352), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.