CVE-2025-68645

HIGH KEV NUCLEI

Zimbra Collaboration Suite 10.0.0-10.0.17 - Unauthenticated Local File Inclusion via RestFilter Servlet

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2025-68645 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added January 22, 2026. EIP tracks 10 public exploits from researchers including iSee857, codeb0ssx, chinaxploiter. A Nuclei detection template is also available.

AI-analyzed exploit summary The repository contains a Python script designed to scan for CVE-2025-68645, a local file inclusion vulnerability in Zimbra Collaboration. It checks for the presence of 'context-param' and 'param-value' in the response from '/h/rest?javax.servlet.include.servlet_path=/WEB-INF/web.xml'.

Description

A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of improper handling of user-supplied request parameters in the RestFilter servlet. An unauthenticated remote attacker can craft requests to the /h/rest endpoint to influence internal request dispatching, allowing inclusion of arbitrary files from the WebRoot directory.

Exploits (10)

github SCANNER 40 stars
by iSee857 · pythonpoc
https://github.com/iSee857/CVE-PoC/tree/main/ZimbraCollaboration-CVE-2025-68645-localInclusion.py

The repository contains a Python script designed to scan for CVE-2025-68645, a local file inclusion vulnerability in Zimbra Collaboration. It checks for the presence of 'context-param' and 'param-value' in the response from '/h/rest?javax.servlet.include.servlet_path=/WEB-INF/web.xml'.

Classification
Scanner 95%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: Zimbra Collaboration
No auth needed
Prerequisites: network access to the target Zimbra instance
mistral-large-3 · analyzed Feb 27, 2026 Full analysis →
nomisec TROJAN 2 stars
by codeb0ssx · poc
https://github.com/codeb0ssx/CVE-2025-68645-PoC

The repository contains obfuscated Python code using PyArmor, a legitimate code protection tool, but the actual exploit logic for CVE-2025-68645 is entirely absent. The payload in CVE-2025-68645.py is a large obfuscated blob with no clear relation to the stated CVE, and the pytransform module is used to load and execute protected code, which is highly suspicious for a PoC.

Classification
Trojan 99%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: Unknown (claimed Zimbra, but no evidence in code)
No auth needed
Prerequisites: Python 2.7 environment · PyArmor runtime
mistral-large-3 · analyzed Jul 18, 2026 Full analysis →
nomisec TROJAN 2 stars
by chinaxploiter · poc
https://github.com/chinaxploiter/CVE-2025-68645-PoC

The repository contains obfuscated Python code using PyArmor, which is highly suspicious and indicative of malicious intent. The lack of clear exploit details and the use of obfuscation suggest this is a deceptive payload rather than a legitimate PoC.

Classification
Trojan 95%
Attack Type
Other
Complexity
Complex
Reliability
Theoretical
Target: unknown
No auth needed
mistral-large-3 · analyzed Feb 19, 2026 Full analysis →
github SCANNER
by 0xBlackash · pythonpoc
https://github.com/0xBlackash/CVE-2025-68645

The repository contains a Python-based scanner for detecting CVE-2025-68645, a Local File Inclusion (LFI) vulnerability in Zimbra Collaboration Suite. It tests multiple payloads against various endpoints to confirm vulnerability but does not include exploit code for actual file retrieval or further exploitation.

Classification
Scanner 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Zimbra Collaboration Suite 10.0 and 10.1
No auth needed
Prerequisites: target URL with vulnerable Zimbra instance
mistral-large-3 · analyzed Apr 25, 2026 Full analysis →
nomisec SCANNER
by Crow5-oss · poc
https://github.com/Crow5-oss/CVE-2025-68645

This repository contains a Python-based scanner for detecting CVE-2025-68645, an LFI vulnerability in Zimbra Collaboration Suite via the `/h/printcalendar` endpoint. It tests multiple payloads targeting the `javax.servlet.include.servlet_path` parameter to identify vulnerable instances.

Classification
Scanner 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Zimbra Collaboration Suite
No auth needed
Prerequisites: network access to target Zimbra instance
mistral-large-3 · analyzed Jun 24, 2026 Full analysis →
nomisec SCANNER
by its970 · poc
https://github.com/its970/CVE-2025-68645

This repository contains a Python-based scanner for detecting CVE-2025-68645, an LFI vulnerability in Zimbra Collaboration Suite via the `/h/printcalendar` endpoint. It tests multiple payloads to identify improper path normalization in the `javax.servlet.include.servlet_path` parameter.

Classification
Scanner 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Zimbra Collaboration Suite
No auth needed
Prerequisites: network access to the target Zimbra instance
mistral-large-3 · analyzed May 30, 2026 Full analysis →
nomisec SCANNER
by CMEGh0stX47 · infoleak
https://github.com/CMEGh0stX47/CVE-2025-68645

This repository contains a Python-based scanner for detecting CVE-2025-68645, an LFI vulnerability in Zimbra Collaboration Suite via the `/h/printcalendar` endpoint. It tests multiple payloads to identify improper path normalization but does not include exploit code for actual file inclusion.

Classification
Scanner 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Zimbra Collaboration Suite
No auth needed
Prerequisites: Network access to the target Zimbra instance
mistral-large-3 · analyzed Feb 22, 2026 Full analysis →
nomisec WRITEUP
by faysalferdous · poc
https://github.com/faysalferdous/CVE-2025-68645-Exploiting-Zimbra-Webmail-LFI-Vulnerability

This repository provides defensive security content for CVE-2025-68645, an LFI vulnerability in Zimbra Classic UI. It includes detection rules, mitigation guidance, and advisory details but explicitly excludes exploit code.

Classification
Writeup 95%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: Zimbra Collaboration (ZCS) 10.0.x and 10.1.x Classic Webmail UI
No auth needed
Prerequisites: Access to the vulnerable Zimbra Classic UI endpoint
mistral-large-3 · analyzed Feb 19, 2026 Full analysis →
nomisec WRITEUP
by MaxMnMl · infoleak
https://github.com/MaxMnMl/zimbramail-CVE-2025-68645-poc

This repository provides a detailed technical analysis of CVE-2025-68645, an LFI vulnerability in Zimbra Collaboration's Webmail Classic UI due to improper input validation in the RestFilter servlet. It includes a PoC request, affected versions, remediation steps, and references.

Classification
Writeup 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Zimbra Collaboration (ZCS) 10.0.x prior to 10.0.18, 10.1.x prior to 10.1.13
No auth needed
Prerequisites: Access to the target Zimbra instance
mistral-large-3 · analyzed Feb 19, 2026 Full analysis →

Nuclei Templates (1)

Zimbra Collaboration - Local File Inclusion
HIGHVERIFIEDby DhiyaneshDk,sirifu4k1
Shodan: http.title:"Zimbra Collaboration Suite"

Scores

CVSS v3 8.8
EPSS 0.3177
EPSS Percentile 98.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact total

Details

CISA KEV 2026-01-22
VulnCheck KEV 2026-01-14
ENISA EUVD EUVD-2025-204719
CWE
CWE-98
Status published
Products (1)
synacor/zimbra_collaboration_suite 10.0.0 - 10.0.18
Published Dec 22, 2025
KEV Added Jan 22, 2026
Tracked Since Feb 18, 2026