Security Advisory

CVE-2025-54391

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-09-16 00:00:00
Last updated 2025-09-17 13:57:52
Assigner mitre
State PUBLISHED

Description

A vulnerability in the EnableTwoFactorAuthRequest SOAP endpoint of Zimbra Collaboration (ZCS) allows an attacker with valid user credentials to bypass Two-Factor Authentication (2FA) protection. The attacker can configure an additional 2FA method (either a third-party authenticator app or email-based 2FA) without presenting a valid authentication token or proving access to an already configured 2FA method. This bypasses 2FA and results in unauthorized access to accounts that are otherwise protected by 2FA.