CVE-2025-68645

HIGH KEV NUCLEI

Zimbra Collaboration Suite 10.0.0-10.0.17 - Unauthenticated Local File Inclusion via RestFilter Servlet

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2025-68645 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added January 22, 2026. EIP tracks 8 public exploits from researchers including iSee857, chinaxploiter, HarisAidhin. A Nuclei detection template is also available.

AI-analyzed exploit summary The repository contains a Python script designed to scan for CVE-2025-68645, a local file inclusion vulnerability in Zimbra Collaboration. It checks for the presence of 'context-param' and 'param-value' in the response from '/h/rest?javax.servlet.include.servlet_path=/WEB-INF/web.xml'.

Description

A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of improper handling of user-supplied request parameters in the RestFilter servlet. An unauthenticated remote attacker can craft requests to the /h/rest endpoint to influence internal request dispatching, allowing inclusion of arbitrary files from the WebRoot directory.

Exploits (8)

github SCANNER 40 stars
by iSee857 · pythonpoc
https://github.com/iSee857/CVE-PoC/tree/main/ZimbraCollaboration-CVE-2025-68645-localInclusion.py

The repository contains a Python script designed to scan for CVE-2025-68645, a local file inclusion vulnerability in Zimbra Collaboration. It checks for the presence of 'context-param' and 'param-value' in the response from '/h/rest?javax.servlet.include.servlet_path=/WEB-INF/web.xml'.

Classification
Scanner 95%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: Zimbra Collaboration
No auth needed
Prerequisites: network access to the target Zimbra instance
devstral-2 · analyzed Feb 27, 2026 Full analysis →
nomisec TROJAN 2 stars
by chinaxploiter · poc
https://github.com/chinaxploiter/CVE-2025-68645-PoC

The repository contains obfuscated Python code using PyArmor, which is highly suspicious and indicative of malicious intent. The lack of clear exploit details and the use of obfuscation suggest this is a deceptive payload rather than a legitimate PoC.

Classification
Trojan 95%
Attack Type
Other
Complexity
Complex
Reliability
Theoretical
Target: unknown
No auth needed
devstral-2 · analyzed Feb 19, 2026 Full analysis →
github SCANNER
by 0xBlackash · pythonpoc
https://github.com/0xBlackash/CVE-2025-68645

The repository contains a Python-based scanner for detecting CVE-2025-68645, a Local File Inclusion (LFI) vulnerability in Zimbra Collaboration Suite. It tests multiple payloads against various endpoints to confirm vulnerability but does not include exploit code for actual file retrieval or further exploitation.

Classification
Scanner 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Zimbra Collaboration Suite 10.0 and 10.1
No auth needed
Prerequisites: target URL with vulnerable Zimbra instance
devstral-2 · analyzed Apr 25, 2026 Full analysis →
nomisec SCANNER
by its970 · poc
https://github.com/its970/CVE-2025-68645

This repository contains a Python-based scanner for detecting CVE-2025-68645, an LFI vulnerability in Zimbra Collaboration Suite via the `/h/printcalendar` endpoint. It tests multiple payloads to identify improper path normalization in the `javax.servlet.include.servlet_path` parameter.

Classification
Scanner 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Zimbra Collaboration Suite
No auth needed
Prerequisites: network access to the target Zimbra instance
devstral-2 · analyzed May 30, 2026 Full analysis →
nomisec SCANNER
by CMEGh0stX47 · infoleak
https://github.com/CMEGh0stX47/CVE-2025-68645

This repository contains a Python-based scanner for detecting CVE-2025-68645, an LFI vulnerability in Zimbra Collaboration Suite via the `/h/printcalendar` endpoint. It tests multiple payloads to identify improper path normalization but does not include exploit code for actual file inclusion.

Classification
Scanner 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Zimbra Collaboration Suite
No auth needed
Prerequisites: Network access to the target Zimbra instance
devstral-2 · analyzed Feb 22, 2026 Full analysis →
nomisec WRITEUP
by faysalferdous · poc
https://github.com/faysalferdous/CVE-2025-68645-Exploiting-Zimbra-Webmail-LFI-Vulnerability

This repository provides defensive security content for CVE-2025-68645, an LFI vulnerability in Zimbra Classic UI. It includes detection rules, mitigation guidance, and advisory details but explicitly excludes exploit code.

Classification
Writeup 95%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: Zimbra Collaboration (ZCS) 10.0.x and 10.1.x Classic Webmail UI
No auth needed
Prerequisites: Access to the vulnerable Zimbra Classic UI endpoint
devstral-2 · analyzed Feb 19, 2026 Full analysis →
nomisec WRITEUP
by MaxMnMl · infoleak
https://github.com/MaxMnMl/zimbramail-CVE-2025-68645-poc

This repository provides a detailed technical analysis of CVE-2025-68645, an LFI vulnerability in Zimbra Collaboration's Webmail Classic UI due to improper input validation in the RestFilter servlet. It includes a PoC request, affected versions, remediation steps, and references.

Classification
Writeup 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Zimbra Collaboration (ZCS) 10.0.x prior to 10.0.18, 10.1.x prior to 10.1.13
No auth needed
Prerequisites: Access to the target Zimbra instance
devstral-2 · analyzed Feb 19, 2026 Full analysis →

Nuclei Templates (1)

Zimbra Collaboration - Local File Inclusion
HIGHVERIFIEDby DhiyaneshDk,sirifu4k1
Shodan: http.title:"Zimbra Collaboration Suite"

Scores

CVSS v3 8.8
EPSS 0.5033
EPSS Percentile 97.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact total

Details

CISA KEV 2026-01-22
VulnCheck KEV 2026-01-14
ENISA EUVD EUVD-2025-204719
CWE
CWE-98
Status published
Products (1)
synacor/zimbra_collaboration_suite 10.0.0 - 10.0.18
Published Dec 22, 2025
KEV Added Jan 22, 2026
Tracked Since Feb 18, 2026