CVE-2025-67809: Medium severity Zimbra Collaboration vulnerability

Published Dec 15, 2025
·
Updated

An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A hardcoded Flickr API key and secret are present in the publicly accessible Flickr Zimlet used by Zimbra Collaboration. Because these credentials are embedded directly in the Zimlet, any unauthorized party could retrieve them and misuse the Flickr integration. An attacker with access to the exposed credentials could impersonate the legitimate application and initiate valid Flickr OAuth flows. If a user is tricked into approving such a request, the attacker could gain access to the user s Flickr data. The hardcoded credentials have since been removed from the Zimlet code, and the associated key has been revoked.

Affected Software

2 affected components
Zimbra Collaboration>=10.0<=10.1
Zimbra Collaboration>=10.0.0<10.1.13

Event History

Dec 15, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-67809?

CVE-2025-67809 has a high severity due to the presence of a hardcoded Flickr API key and secret in Zimbra Collaboration.

2

How do I fix CVE-2025-67809?

To fix CVE-2025-67809, you should update to a patched version of Zimbra Collaboration that removes the hardcoded API credentials.

3

What versions are affected by CVE-2025-67809?

CVE-2025-67809 affects Zimbra Collaboration versions 10.0 and 10.1.

4

What potential risks are associated with CVE-2025-67809?

The risks include unauthorized access and exploitation of the exposed Flickr API key, which could lead to data breaches or service disruption.

5

Is there a workaround for CVE-2025-67809 until I can update?

Disabling the affected Flickr Zimlet can serve as a temporary workaround while you plan to update Zimbra Collaboration.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203