CVE-2022-41352CISA KEVEPSS p99.9%

CVE-2022-41352CVE-2022-41352

synacor / zimbra_collaboration_suite

Description

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavis via a cpio loophole (extraction to /opt/zimbra/jetty/webapps/zimbra/public) that can lead to incorrect access to any other user accounts. Zimbra recommends pax over cpio. Also, pax is in the prerequisites of Zimbra on Ubuntu; however, pax is no longer part of a default Red Hat installation after RHEL 6 (or CentOS 6). Once pax is installed, amavis automatically prefers it over cpio.

Scoring

CVSS 9.8 ()
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS95.48% probability of exploitation · percentile 99.9% · 2026-06-17T12:03:21Z
Last modified2026-06-17

CISA KEV entry

Added to KEV: 2022-10-20

(incoming)1

TypeTargetConfidenceTier
KEVEntrySynacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerabilitykev-cve-2022-413520%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability
CVE
Synacor Zimbra Collaboration Suite (ZCS) Authentication Bypass Vulnerability
CVE
Synacor Zimbra Collaboration Suite (ZCS) Command Injection Vulnerability
CVE
Synacor Zimbra Collaboration Suite (ZCS) Command Execution Vulnerability
CVE
Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting Vulnerability
CVE
Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability
Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.