CVE-2025-68645 Details
Description
A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of improper handling of user-supplied request parameters in the RestFilter servlet. An unauthenticated remote attacker can craft requests to the /h/rest endpoint to influence internal request dispatching, allowing inclusion of arbitrary files from the WebRoot directory.
A Local File Inclusion (LFI) vulnerability has been identified in the Webmail Classic UI of Zimbra Collaboration (ZCS) versions 10.0 and 10.1. This vulnerability arises from improper handling of user-supplied request parameters in the RestFilter servlet, allowing an unauthenticated remote attacker to craft requests that influence internal request dispatching. This manipulation can lead to the inclusion of arbitrary files from the WebRoot directory.
Users can upgrade to ZCS versions 10.1.13 or 10.0.18, both released on November 6, 2025, which include patches for this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-68645 | CISA-ADP | US Government Resource |
| https://wiki.zimbra.com/wiki/Security_Center | [email protected] | Release NotesVendor Advisory |
| https://wiki.zimbra.com/wiki/Zimbra_Responsible_Disclosure_Policy | [email protected] | Product |
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability | Jan 22, 2026 | Feb 12, 2026 | Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-98 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| synacor zimbra collaboration suite | >= 10.0.0, < 10.0.18 >= 10.1.0, < 10.1.13 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jan 23, 2026 | Modified Analysis | [email protected] |
| Jan 22, 2026 | CVE Modified | CISA-ADP |
| Jan 2, 2026 | Initial Analysis | [email protected] |
| Dec 22, 2025 | CVE Modified | CISA-ADP |
| Dec 22, 2025 | New CVE Received | [email protected] |