CVE-2025-67809
Zimbra Collaboration Server vulnerability analysis and mitigation

Overview

CVE-2025-67809 is a hardcoded credentials vulnerability (CWE-798) in the Flickr Zimlet component of Zimbra Collaboration (ZCS) versions 10.0.0 through 10.1.12. A Flickr API key and secret were embedded directly in the publicly accessible Zimlet code, allowing any party to retrieve and misuse these credentials. The vulnerability was published on December 15, 2025, and affects Zimbra Collaboration versions starting from 10.0.0 up to (but not including) 10.1.13. It carries a CVSS v3.1 base score of 4.7 (Medium) (Red Hat CVE, Zimbra Advisories).

Technical details

The root cause is the use of hard-coded credentials (CWE-798) in the Flickr Zimlet shipped with Zimbra Collaboration. Because the Zimlet is publicly accessible, any unauthenticated party can retrieve the embedded Flickr API key and secret by inspecting the Zimlet's source code or downloaded package. With these credentials, an attacker can impersonate the legitimate Zimbra application and initiate valid Flickr OAuth authorization flows. Exploitation requires no privileges on the Zimbra server itself, but does require user interaction — specifically, a victim must be socially engineered into approving a malicious OAuth request crafted by the attacker using the stolen credentials (Red Hat CVE, Zimbra Advisories).

Impact

If a user is deceived into approving an attacker-initiated OAuth flow using the exposed credentials, the attacker gains access to that user's Flickr account data, including photos and associated personal information. The confidentiality and integrity impacts are limited to the Flickr integration scope — there is no direct impact on the Zimbra server itself, its email data, or other connected services. Availability is not affected. The vulnerability does not enable lateral movement within the Zimbra environment or broader infrastructure (Red Hat CVE).

Exploitability

There is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation as of the time of this report (Zimbra Advisories). The EPSS score is approximately 0.026% (0.000260), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is constrained by the requirement for user interaction (victim must approve an OAuth request) and high attack complexity, limiting its practical weaponization (Red Hat CVE).

Exploitation steps

  1. Obtain the hardcoded credentials: Download or inspect the publicly accessible Flickr Zimlet from a vulnerable Zimbra Collaboration instance (versions 10.0.0–10.1.12) and extract the embedded Flickr API key and secret from the Zimlet source code.
  2. Register a malicious OAuth application: Use the extracted API key and secret to configure an application that can initiate Flickr OAuth authorization flows, impersonating the legitimate Zimbra Flickr integration.
  3. Craft a phishing lure: Construct a Flickr OAuth authorization URL using the stolen credentials and deliver it to a target Zimbra user via phishing email, social engineering, or a malicious link, making it appear as a legitimate Zimbra-Flickr integration request.
  4. Harvest OAuth token: If the victim approves the OAuth request, the attacker receives an OAuth access token granting access to the victim's Flickr account data, including photos and profile information (Red Hat CVE, Zimbra Advisories).

Mitigation and workarounds

Zimbra has addressed this vulnerability in Zimbra Collaboration version 10.1.13 by removing the hardcoded credentials from the Flickr Zimlet code and revoking the associated Flickr API key. Administrators should upgrade all affected Zimbra Collaboration instances (10.0.0–10.1.12) to version 10.1.13 or later as the primary remediation. No configuration-based workaround is available; disabling or removing the Flickr Zimlet on unpatched instances can reduce exposure until an upgrade is possible (Zimbra Advisories).

Community reactions

The vulnerability received limited community attention, with brief mentions on security-focused social media such as Mastodon (infosec.exchange) and coverage in automated vulnerability tracking platforms. No significant vendor statements beyond the Zimbra security advisory, and no notable independent researcher commentary or major media coverage has been identified for this specific CVE (Zimbra Advisories).

Additional resources


SourceThis report was generated using AI

Related Zimbra Collaboration Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-73576MEDIUM6.3
  • Zimbra Collaboration Server logoZimbra Collaboration Server
  • cpe:2.3:a:zimbra:collaboration
NoYesAug 13, 2026
CVE-2026-73572MEDIUM6.1
  • Zimbra Collaboration Server logoZimbra Collaboration Server
  • cpe:2.3:a:zimbra:collaboration
NoYesAug 13, 2026
CVE-2026-73575LOW3.1
  • Zimbra Collaboration Server logoZimbra Collaboration Server
  • cpe:2.3:a:zimbra:collaboration
NoYesAug 13, 2026
CVE-2026-73574LOW3.1
  • Zimbra Collaboration Server logoZimbra Collaboration Server
  • cpe:2.3:a:zimbra:collaboration
NoYesAug 13, 2026
CVE-2026-73573LOW3.1
  • Zimbra Collaboration Server logoZimbra Collaboration Server
  • cpe:2.3:a:zimbra:collaboration
NoYesAug 13, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management