Zimbra Collaboration Suite (ZCS) is a mail and groupware platform whose server side is a Java application, mailboxd, running in Jetty, fronted by an nginx proxy and supported by memcached (route and auth caching), amavis/clamav (mail scanning), and MariaDB. Users reach the web client on 443 under /zimbra/; administrators use a separate console on 7071 under /zimbraAdmin/. Almost every server function, user and admin alike, is driven by a SOAP API: user operations at /service/soap, privileged operations at /service/admin/soap, with authentication carried by the ZM_AUTH_TOKEN (user) and ZM_ADMIN_AUTH_TOKEN (admin) cookies.
That architecture is why Zimbra is a rich target. The nginx-to-mailboxd proxying, the SOAP token model, and the many extensions (mboximport, Autodiscover, the ProxyServlet) have each produced reachable, often unauthenticated, paths to a web shell or an admin token. The SOAP API also leaks account information before authentication, giving a clean enumeration step that feeds everything after it.
Triage#
Confirm Zimbra and pin the build; the RCE chains are strictly version-bound.
curl -sk https://<target>/zimbra/ -i | grep -iE 'set-cookie|location' # user client
curl -sk https://<target>:7071/zimbraAdmin/ -i | head # admin console
curl -sk https://<target>/service/admin/soap -i | head # admin SOAP endpoint
# version from client asset paths
curl -sk https://<target>/zimbra/ | grep -oE 'skins|/js/[0-9]+\.[0-9]+[^"]*' | head
The cookies ZM_AUTH_TOKEN/ZM_ADMIN_AUTH_TOKEN, the /service/soap and /service/admin/soap endpoints, and the 7071 admin console together confirm ZCS. The build string surfaces in the client JS asset paths and, with local access, from zmcontrol -v. Record the exact patch level: it decides which of the RCE chains below is live.
Pages#
- Enumeration: account and version discovery through the public SOAP endpoint and login differentials before you hold any token.
- Authentication bypass: obtaining or forging a valid auth token, including admin-to-user impersonation via
DelegateAuthRequestand the token-handling flaws that mint a token without credentials. - RCE chains: the unauthenticated
mboximportweb-shell write, the memcached CRLF response injection, the ProxyServlet SSRF to the admin SOAP, and the Autodiscover XXE, each ending in code execution on the server.