TECHNOLOGIES: ZIMBRA

Zimbra Security Review

Zimbra’s admin console, Class of Service and two-factor settings enforce exactly what your team configured, defaults or gaps included. We test which rights, policies and sync permissions actually apply to your accounts. CREST-certified testers, fixed price from £2,840 for a 2-day single-platform scope, quoted within 24 hours.

  • Unlimited retesting
  • Unlimited pre-retesting
  • No hidden fees
Accredited & recognised
Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified Crown Commercial Service supplier UK Cyber Security Council member
CREST
Approved Provider
10
Zimbra Test Areas
FREE
Retest Until Closed
24h
Scope to Active Test
CLIENT REFERENCE
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
SquareOneImran SaghirProject Lead, SquareOneRead the SquareOne case study →
CLIENT REFERENCE
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
CelloriDan WilcocksonFounder, CelloriRead the Cellori case study →
See all case studies →
WHY IT MATTERS
COS

Every Zimbra account inherits its quotas, password policy, two-factor rules and web client access from a single Class of Service object, so one broadly configured COS hands the same gap to every account assigned to it.

Zimbra risk sits in Class of Service inheritance, delegated admin rights and two-factor configuration

Zimbra’s own documentation sets out how administration is meant to work: a Global Administrator holds full privileges over every domain, account and server, while a Delegated Administrator only receives the preset, attribute and combo rights a Global Administrator chose to grant. Every account also inherits its quotas, password policy, attachment rules and two-factor settings from a single Class of Service object, so the same COS gap reaches every account assigned to it. We test which rights each delegated role actually holds and which Class of Service each account is really running under, not what the naming implies.

Two-factor authentication is enabled and made mandatory per Class of Service, using a six-digit code that changes every 15 seconds, but Zimbra’s own two-factor authentication documentation also describes two ways around that code: marking the web client as a trusted device, which then accepts a password alone, and generating an application passcode for IMAP or ActiveSync clients that cannot show the TOTP prompt at all. We test whether either bypass is switched on where it should not be, and whether an old application passcode still works after the account owner has moved on.

Zimbra also supports preauth, a single sign-on mechanism where a shared domain key lets a trusted application mint a valid Zimbra session without a password, and Zimbra’s own documentation notes that whoever holds that key can generate a token for any user in the domain. Folders, calendars and Briefcase files carry the same flexibility: an owner can share with a named internal colleague, an external guest who needs a password, or anyone who has the link at all. It is the same configuration-versus-platform question we test on Microsoft 365 mailboxes and calendars.

SCOPE

What we pen test on a Zimbra instance

ZM-01

Global Administrator and Delegated Administrator Rights

Zimbra separates a Global Administrator, who holds full privileges over every domain, server and account, from a Delegated Administrator, who only receives the rights a Global Administrator chose to grant, down to two predefined roles for domain administration and distribution list management. We test which rights each delegated administrator account actually holds against the domain or list it is meant to manage, and whether a role built for one task quietly reaches further.

ZM-02

Attribute and Combo Rights Behind a Delegated Role

Delegated administration is built from three right types: preset rights tied to one fixed target such as creating an account, attribute rights that grant access to a single LDAP attribute, and combo rights that bundle several preset and attribute rights into one role. We test whether a combo right created for a narrow task, such as resetting passwords for one distribution list, also carries attribute rights that expose data outside that list.

ZM-03

Class of Service Password and Lockout Policy

The password and failed-login policy for every account comes from its Class of Service, and Zimbra’s own defaults allow a password as short as six characters and ten failed attempts before a one-hour lockout. We test the actual password and lockout values configured on the Class of Service your accounts use, not the shipped defaults, and how they hold up against a sustained credential-stuffing attempt.

ZM-04

Two-Factor Authentication Enforcement per Class of Service

Two-factor authentication in Zimbra is enabled and made mandatory at the Class of Service level using a six-digit, time-based code that expires after 15 seconds, so an account can sit in a Class of Service where 2FA is available but never required. We test which Class of Service your admin and standard accounts actually use, and whether two-factor authentication is genuinely mandatory for the accounts that need it.

ZM-05

Trusted Device Bypass for Two-Factor Authentication

During the second stage of two-factor login, a user can mark the Zimbra Web Client or Touch Client as a trusted device, after which that device only needs a password and the two-factor code is skipped entirely. We test whether trusted devices are switched on where they should not be, and whether a stolen or shared browser session on a trusted device grants that same password-only access.

ZM-06

Application Passcodes for Mobile Sync and IMAP

IMAP and ActiveSync clients cannot display the two-factor prompt, so Zimbra issues a separate application passcode for each client that signs straight in without the six-digit code, and only changing the account password revokes every passcode issued. We test how many application passcodes exist per account, whether old ones from a decommissioned phone or mail client are ever revoked, and what mailbox access a single passcode grants.

ZM-07

Preauth Domain Key and Single Sign-On Trust

Preauth lets a trusted application sign a user into Zimbra without a password, using a domain-wide key to compute the authentication token, and Zimbra’s own documentation is explicit that whoever holds that key can generate a valid token for any user in the domain. We test how that key is stored and reached, and whether the systems allowed to use it are actually limited to the ones your organisation intended.

ZM-08

Account and Domain Status Controls

An account status of Active, Locked, Maintenance, Pending or Closed decides whether that user can log in and whether mail keeps being delivered, and a domain-level status change can override every account status underneath it. We test whether offboarded or suspected-compromised accounts actually carry the status your process assumes, rather than a password reset alone.

ZM-09

Distribution List Membership and GAL Visibility

A distribution list can be hidden from the Global Address List, but that setting has to be applied deliberately, and every list left visible exposes its full membership to anyone who can browse or autocomplete the GAL. We test which distribution lists are visible in your GAL, whether sensitive lists such as finance or security teams are actually hidden, and what an authenticated account can enumerate about the rest.

ZM-10

Folder, Calendar and Briefcase Sharing Permissions

When sharing is enabled, a user can grant an internal colleague full manager access to a mail folder, calendar or Briefcase file, hand an external guest a password-protected link, or publish it so that anyone with the URL can view the contents. We test which of your users’ shares fall into each of those three tiers, and whether a share meant for one guest is actually reachable by anyone who finds the link.

OUR PROCESS

Zimbra Security Review: From Scope to Attestation

01

Scope and Access

We agree which domains, Classes of Service and admin roles are in scope, plus at least one standard account and one delegated or global admin account for testing.

02

Rights and Configuration Mapping

We map delegated admin rights, Class of Service password and two-factor settings, and preauth or sharing configuration against Zimbra’s own administration guide.

03

Manual Testing

CREST-certified testers manually test admin rights, two-factor bypass paths, application passcodes and sharing permissions, chaining findings where they compound.

04

Attestation and Retest

You get a technical report with CVSS scores and reproduction steps, a walkthrough call, a free retest once fixes are deployed, and an attestation letter for auditors.

CREDENTIALS

Verified Accreditations Auditors Accept

Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.

GET YOUR QUOTE

Get a CREST Zimbra pen test quote in 24 hours

A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.

  • CREST and IASME accredited. Testing your auditors and clients already recognise.
  • Fast-track testing within 24 hours where required. Free retest of every fix included.
  • Live findings via your client portal, not a four-week PDF.
  • Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
What clients say
There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.
CelloriDan WilcocksonFounder, Cellori

Under NDA Further named references available on a scoping call.

What happens next
  1. We reply within one business day with a fixed-price quote from a named CREST assessor.
  2. You approve the scope and we book a start date, usually within 24 hours.
  3. Live findings land in your client portal as we test, with a free retest of every fix.
Accredited & recognised
CREST member Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified UK Cyber Security Council Crown Commercial Service supplier

Get your fixed pen test quote in 24 hours

⚡24h reply ✓CREST tester ↻Free retests

or book a 20-min scoping call first

We reply within one business day. Your data stays with us. No newsletter signup.

COMPLIANCE READY

Reports Mapped to Every Framework

Findings are written so your team can reference the report against each framework without translation work.

ISO 27001:2022

Annex A.8.8 management of technical vulnerabilities plus A.5.15-5.18 and A.8.2-8.5 access control validation.

SOC 2 Type I & II

CC6 logical access, CC7 system operations, CC8 change management evidence.

PCI DSS

Requirement 11.4 application penetration testing across cardholder data environments, including ecommerce penetration testing for online retail platforms.

FCA SYSC

SYSC 4.1.1R, 6.1.1R, 13 mapped to each finding for FCA-regulated firms.

UK GDPR

Article 32 effectiveness testing, customer-data security controls, ICO-acceptable evidence.

Cyber Essentials Plus

Direct certification through our IASME body status, single-vendor delivery.

PRICING

Transparent Zimbra Security Review Pricing

Pricing depends on the number of roles, integrations and environments in scope. See our pricing page for how we quote.

✦ ALWAYS · ON EVERY TIER · NO EXCEPTIONS ✦
✓Free retests, no time limit
✓Free rescheduling
✓No cancellation fees
✓24-hour scope to active testing
✓Live findings to client portal
✓Executive + technical report
✓60-min walkthrough call
✓Letter of attestation
SMALL / SMB
£2,840–£4,390
2 to 4 testing days

Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.

Get a fixed quote
ENTERPRISE
£6,780–£9,520
5 to 7 testing days

Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.

Get a fixed quote

Full UK pen test cost guide

WHY EJN LABS

What You Get From Zimbra Security Review

Six concrete differentiators competitors don’t all match.

CREST-Certified Testers, Verifiable

Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.

24-Hour Startup, Where Required

From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.

Live Findings, Not 4-Week PDFs

Critical issues reported during testing through your client portal. Your team remediates while testing continues.

Audit-Ready Reports

Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).

Free Retests, Standard

Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.

UK-Based CREST Testers

Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.

FAQ

Frequently Asked

What access do you need to test our Zimbra deployment?

We need at least one standard user account and one delegated or global administrator account, plus details of any Classes of Service, distribution lists or mobile sync policies you want included. If preauth or single sign-on is configured, tell us during scoping so we can test it alongside standard login.

Will testing touch our live data?

We test whichever environment you give us access to. If that is production, we agree exclusions upfront, such as bulk deletes or mass distribution list changes, and we do not run destructive tests against real mailboxes without that agreement in writing.

How long does a Zimbra security review take?

A single Zimbra deployment sits in our 2-day single-platform scope, with a report typically landing around 5 working days after kickoff. A deployment with multiple domains, heavy delegated administration or a large distribution list structure moves into a wider scope with more testing days.

Do you test self-hosted Zimbra as well as hosted deployments?

Yes. We test Zimbra running on your own servers the same way as a deployment hosted by a managed provider, adjusting the self-hosted checks, such as admin console exposure and server-level access, to whichever hosting model you use.

What is out of scope for a single-platform Zimbra test?

Infrastructure underneath Zimbra, such as the host operating system, network or mail transfer agent configuration, is out of scope for this test and covered by our Linux server or cloud testing instead. A separate application that only happens to integrate with Zimbra, such as a connected identity provider, is scoped and quoted separately.

Do you need our source code or root server access?

No. Testing is black-box against the accounts and access you provide by default. A grey-box option, where we review relevant Class of Service settings, delegated admin rights and preauth configuration alongside testing, is available for faster or deeper coverage of specific findings.

Does Zimbra have a vendor security or disclosure policy we need to follow?

Zimbra publishes a responsible disclosure policy for researchers reporting vulnerabilities in the product itself, rather than a customer penetration-testing authorisation scheme, since a Zimbra deployment typically runs on infrastructure you or your hosting provider control rather than shared vendor infrastructure. We confirm current terms with you and, where relevant, your hosting provider during scoping, before testing starts.

Are your testers CREST certified?

Yes. Every Zimbra engagement is carried out by UK-based, CREST-certified testers, and your report and attestation letter are recognised by auditors and insurers accordingly.

EXPLORE EVERY SERVICE

20+ CREST-accredited testing services in one place

Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.

Penetration testing services
READY TO START

Get a fixed price for your Zimbra instance

Zimbra’s admin console, Class of Service and two-factor settings enforce exactly what your team configured, defaults or gaps included. We test which rights, policies and sync permissions actually apply to your accounts. CREST-certified testers, fixed price from £2,840 for a 2-day single-platform scope, quoted within 24 hours.