CVE-2025-68645
HIGH KEV NUCLEIZimbra Collaboration <10.2 - LFI
Title source: llmDescription
A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of improper handling of user-supplied request parameters in the RestFilter servlet. An unauthenticated remote attacker can craft requests to the /h/rest endpoint to influence internal request dispatching, allowing inclusion of arbitrary files from the WebRoot directory.
Exploits (6)
github
SCANNER
40 stars
by iSee857 · pythonpoc
https://github.com/iSee857/CVE-PoC/tree/main/ZimbraCollaboration-CVE-2025-68645-localInclusion.py
nomisec
WRITEUP
by faysalferdous · poc
https://github.com/faysalferdous/CVE-2025-68645-Exploiting-Zimbra-Webmail-LFI-Vulnerability
Nuclei Templates (1)
Zimbra Collaboration - Local File Inclusion
HIGHVERIFIEDby DhiyaneshDk,sirifu4k1
Shodan:
http.title:"Zimbra Collaboration Suite"
Scores
CVSS v3
8.8
EPSS
0.4707
EPSS Percentile
97.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Details
CISA KEV
2026-01-22
VulnCheck KEV
2026-01-14
ENISA EUVD
EUVD-2025-204719
CWE
CWE-98
Status
published
Products (1)
synacor/zimbra_collaboration_suite
10.0.0 - 10.0.18
Published
Dec 22, 2025
KEV Added
Jan 22, 2026
Tracked Since
Feb 18, 2026