Vulnerability record · CVE-2025-68645 · published 22 December 2025
CVE-2025-68645: Zimbra Webmail Classic UI RestFilter local file inclusion
SSynacor · Zimbra Collaboration Suite
Zimbra Collaboration Suite 10.0 and 10.1 mishandle user-supplied parameters in the RestFilter servlet of the Webmail Classic UI, allowing local file inclusion via crafted requests to the /h/rest endpoint. Because the flaw permits inclusion of arbitrary files from the WebRoot directory, it exposes server-side files to an unauthenticated remote attacker. The record does not specify which exact files can be read or whether code execution follows from the inclusion.
Description
A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of improper handling of user-supplied request parameters in the RestFilter servlet. An unauthenticated remote attacker can craft requests to the /h/rest endpoint to influence internal request dispatching, allowing inclusion of arbitrary files from the WebRoot directory.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
critical priorityThe flaw is remotely reachable without authentication, rated CVSS 8.8, and listed in CISA KEV with known exploitation and a near-term remediation deadline.
What it is
Zimbra Collaboration Suite 10.0 and 10.1 mishandle user-supplied parameters in the RestFilter servlet of the Webmail Classic UI, allowing local file inclusion via crafted requests to the /h/rest endpoint. Because the flaw permits inclusion of arbitrary files from the WebRoot directory, it exposes server-side files to an unauthenticated remote attacker. The record does not specify which exact files can be read or whether code execution follows from the inclusion.
Impact
An attacker can read arbitrary files from the WebRoot directory without authenticating, potentially exposing configuration, credential or application data. The CVSS vector also rates integrity and availability impact as high, but the description only substantiates file disclosure.
Attack surface
Reached over the network through the /h/rest endpoint of the Webmail Classic UI; no authentication is required (PR:N), though the CVSS vector requires user interaction (UI:R), which the description does not explain.
Exploitation
CVE-2025-68645 was added to CISA KEV on 2026-01-22 with a remediation due date of 2026-02-12, indicating known exploitation. EPSS gives a 30-day probability of 0.49374 (98.8th percentile), and no ransomware campaign use is documented.
What to do
- Apply the vendor mitigation or fixed release per the Zimbra Security Center advisory; treat this as urgent given the KEV listing.
- If patching is not immediately possible, restrict or block external access to the /h/rest endpoint and the Webmail Classic UI.
- Follow BOD 22-01 guidance for cloud services or discontinue use of the product if no mitigation is available.
- Review and rotate credentials and secrets stored in files under the WebRoot that could have been exposed.
Detection
- Hunt web and proxy logs for requests to /h/rest with unusual or traversal-style parameters, especially from unauthenticated sources.
- Alert on access to the Webmail Classic UI RestFilter servlet from unexpected IPs or user agents.
- Monitor file access to WebRoot paths for reads initiated by the webmail process outside normal operation.
- Correlate any /h/rest activity with subsequent authentication attempts or outbound connections from the Zimbra host.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-68645 to the Known Exploited Vulnerabilities catalog on 22 January 2026 as "Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 12 February 2026.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://wiki.zimbra.com/wiki/Security_Center | Release NotesVendor Advisory |
| https://wiki.zimbra.com/wiki/Zimbra_Responsible_Disclosure_Policy | Product |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-68645 | US Government Resource |
Track CVE-2025-68645 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-68645), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.