CVE-2025-54391: Critical severity Zimbra Collaboration vulnerability
A vulnerability in the EnableTwoFactorAuthRequest SOAP endpoint of Zimbra Collaboration (ZCS) allows an attacker with valid user credentials to bypass Two-Factor Authentication (2FA) protection. The attacker can configure an additional 2FA method (either a third-party authenticator app or email-based 2FA) without presenting a valid authentication token or proving access to an already configured 2FA method. This bypasses 2FA and results in unauthorized access to accounts that are otherwise protected by 2FA.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54391?
CVE-2025-54391 is considered critical due to its potential to bypass Two-Factor Authentication for Zimbra Collaboration users.
How do I fix CVE-2025-54391?
To mitigate CVE-2025-54391, update your Zimbra Collaboration software to the latest version provided by Zimbra that addresses this vulnerability.
Who is affected by CVE-2025-54391?
Any user with valid credentials using Zimbra Collaboration who has Two-Factor Authentication enabled is affected by CVE-2025-54391.
What are the impacts of CVE-2025-54391?
CVE-2025-54391 allows an attacker to bypass Two-Factor Authentication, potentially leading to unauthorized access to user accounts.
Is there a workaround for CVE-2025-54391?
Currently, the best practice is to immediately apply available patches and monitor user accounts for any suspicious activity as a temporary workaround for CVE-2025-54391.