Zimbra Collaboration Suite 8.8.15/9.0 - Zip Path Traversal
CVE-2022-27925
Early Release
Description
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated user with administrator rights has the ability to upload arbitrary files to the system, leading to directory traversal.
Severity
High
CVSS Score
7.2
Exploit Probability
99%
Affected Product
zimbra_collaboration_suite
Published Date
September 2, 2026
Template Author
popy21
CVE-2022-27925.yaml
7.2Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2022-27925
CWE ID:
cwe-22
References
http://packetstormsecurity.com/files/168146/Zimbra-Zip-Path-Traversal.htmlhttps://wiki.zimbra.com/wiki/Security_Centerhttps://wiki.zimbra.com/wiki/Zimbra_Releases/9.0.0/P24https://wiki.zimbra.com/wiki/Zimbra_Releases/8.8.15/P31https://wiki.zimbra.com/wiki/Zimbra_Security_Advisorieshttps://www.volexity.com/blog/2022/08/10/mass-exploitation-of-unauthenticated-zimbra-rce-cve-2022-27925/https://nvd.nist.gov/vuln/detail/CVE-2022-27925
Remediation Steps
Apply Zimbra Collaboration 8.8.15 Patch 31 or 9.0.0 Patch 24 (both released 2022-03-30) or later, which also requires the CVE-2022-37042 fix in 8.8.15 Patch 33 / 9.0.0 Patch 26 to close the authentication bypass on the same mboximport endpoint.