#VU118168 PHP file inclusion in Zimbra Collaboration - CVE-2025-68645

 

#VU118168 PHP file inclusion in Zimbra Collaboration - CVE-2025-68645

Published: November 6, 2025 / Updated: January 22, 2026


Vulnerability identifier: #VU118168
Vulnerability risk: Critical
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Red
CVE-ID: CVE-2025-68645
CWE-ID: CWE-98
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Zimbra Collaboration
Software vendor:
Synacor Inc.

Description

The vulnerability allows a remote attacker to include and execute arbitrary PHP files on the server.

The vulnerability exists due to incorrect input validation when including PHP files in the RestFilter. A remote non-authenticated attacker can send a specially crafted HTTP request to the affected application, include and execute arbitrary PHP code on the system with privileges of the web server.


Remediation

Install updates from vendor's website.

External links