Zimbra Security Review
Zimbra’s admin console, Class of Service and two-factor settings enforce exactly what your team configured, defaults or gaps included. We test which rights, policies and sync permissions actually apply to your accounts. CREST-certified testers, fixed price from £2,840 for a 2-day single-platform scope, quoted within 24 hours.
- Unlimited retesting
- Unlimited pre-retesting
- No hidden fees
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
Every Zimbra account inherits its quotas, password policy, two-factor rules and web client access from a single Class of Service object, so one broadly configured COS hands the same gap to every account assigned to it.
Zimbra risk sits in Class of Service inheritance, delegated admin rights and two-factor configuration
Zimbra’s own documentation sets out how administration is meant to work: a Global Administrator holds full privileges over every domain, account and server, while a Delegated Administrator only receives the preset, attribute and combo rights a Global Administrator chose to grant. Every account also inherits its quotas, password policy, attachment rules and two-factor settings from a single Class of Service object, so the same COS gap reaches every account assigned to it. We test which rights each delegated role actually holds and which Class of Service each account is really running under, not what the naming implies.
Two-factor authentication is enabled and made mandatory per Class of Service, using a six-digit code that changes every 15 seconds, but Zimbra’s own two-factor authentication documentation also describes two ways around that code: marking the web client as a trusted device, which then accepts a password alone, and generating an application passcode for IMAP or ActiveSync clients that cannot show the TOTP prompt at all. We test whether either bypass is switched on where it should not be, and whether an old application passcode still works after the account owner has moved on.
Zimbra also supports preauth, a single sign-on mechanism where a shared domain key lets a trusted application mint a valid Zimbra session without a password, and Zimbra’s own documentation notes that whoever holds that key can generate a token for any user in the domain. Folders, calendars and Briefcase files carry the same flexibility: an owner can share with a named internal colleague, an external guest who needs a password, or anyone who has the link at all. It is the same configuration-versus-platform question we test on Microsoft 365 mailboxes and calendars.
SCOPE
What we pen test on a Zimbra instance
Global Administrator and Delegated Administrator Rights
Zimbra separates a Global Administrator, who holds full privileges over every domain, server and account, from a Delegated Administrator, who only receives the rights a Global Administrator chose to grant, down to two predefined roles for domain administration and distribution list management. We test which rights each delegated administrator account actually holds against the domain or list it is meant to manage, and whether a role built for one task quietly reaches further.
Attribute and Combo Rights Behind a Delegated Role
Delegated administration is built from three right types: preset rights tied to one fixed target such as creating an account, attribute rights that grant access to a single LDAP attribute, and combo rights that bundle several preset and attribute rights into one role. We test whether a combo right created for a narrow task, such as resetting passwords for one distribution list, also carries attribute rights that expose data outside that list.
Class of Service Password and Lockout Policy
The password and failed-login policy for every account comes from its Class of Service, and Zimbra’s own defaults allow a password as short as six characters and ten failed attempts before a one-hour lockout. We test the actual password and lockout values configured on the Class of Service your accounts use, not the shipped defaults, and how they hold up against a sustained credential-stuffing attempt.
Two-Factor Authentication Enforcement per Class of Service
Two-factor authentication in Zimbra is enabled and made mandatory at the Class of Service level using a six-digit, time-based code that expires after 15 seconds, so an account can sit in a Class of Service where 2FA is available but never required. We test which Class of Service your admin and standard accounts actually use, and whether two-factor authentication is genuinely mandatory for the accounts that need it.
Trusted Device Bypass for Two-Factor Authentication
During the second stage of two-factor login, a user can mark the Zimbra Web Client or Touch Client as a trusted device, after which that device only needs a password and the two-factor code is skipped entirely. We test whether trusted devices are switched on where they should not be, and whether a stolen or shared browser session on a trusted device grants that same password-only access.
Application Passcodes for Mobile Sync and IMAP
IMAP and ActiveSync clients cannot display the two-factor prompt, so Zimbra issues a separate application passcode for each client that signs straight in without the six-digit code, and only changing the account password revokes every passcode issued. We test how many application passcodes exist per account, whether old ones from a decommissioned phone or mail client are ever revoked, and what mailbox access a single passcode grants.
Preauth Domain Key and Single Sign-On Trust
Preauth lets a trusted application sign a user into Zimbra without a password, using a domain-wide key to compute the authentication token, and Zimbra’s own documentation is explicit that whoever holds that key can generate a valid token for any user in the domain. We test how that key is stored and reached, and whether the systems allowed to use it are actually limited to the ones your organisation intended.
Account and Domain Status Controls
An account status of Active, Locked, Maintenance, Pending or Closed decides whether that user can log in and whether mail keeps being delivered, and a domain-level status change can override every account status underneath it. We test whether offboarded or suspected-compromised accounts actually carry the status your process assumes, rather than a password reset alone.
Distribution List Membership and GAL Visibility
A distribution list can be hidden from the Global Address List, but that setting has to be applied deliberately, and every list left visible exposes its full membership to anyone who can browse or autocomplete the GAL. We test which distribution lists are visible in your GAL, whether sensitive lists such as finance or security teams are actually hidden, and what an authenticated account can enumerate about the rest.
Folder, Calendar and Briefcase Sharing Permissions
When sharing is enabled, a user can grant an internal colleague full manager access to a mail folder, calendar or Briefcase file, hand an external guest a password-protected link, or publish it so that anyone with the URL can view the contents. We test which of your users’ shares fall into each of those three tiers, and whether a share meant for one guest is actually reachable by anyone who finds the link.
OUR PROCESS
Zimbra Security Review: From Scope to Attestation
Scope and Access
We agree which domains, Classes of Service and admin roles are in scope, plus at least one standard account and one delegated or global admin account for testing.
Rights and Configuration Mapping
We map delegated admin rights, Class of Service password and two-factor settings, and preauth or sharing configuration against Zimbra’s own administration guide.
Manual Testing
CREST-certified testers manually test admin rights, two-factor bypass paths, application passcodes and sharing permissions, chaining findings where they compound.
Attestation and Retest
You get a technical report with CVSS scores and reproduction steps, a walkthrough call, a free retest once fixes are deployed, and an attestation letter for auditors.
CREDENTIALS
Verified Accreditations Auditors Accept
Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.
GET YOUR QUOTE
Get a CREST Zimbra pen test quote in 24 hours
A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.
- CREST and IASME accredited. Testing your auditors and clients already recognise.
- Fast-track testing within 24 hours where required. Free retest of every fix included.
- Live findings via your client portal, not a four-week PDF.
- Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
Under NDA Further named references available on a scoping call.
- We reply within one business day with a fixed-price quote from a named CREST assessor.
- You approve the scope and we book a start date, usually within 24 hours.
- Live findings land in your client portal as we test, with a free retest of every fix.
Get your fixed pen test quote in 24 hours
Quote request received
We will reply within one business day with your fixed-price quote from a named CREST assessor.
Your data stays with us. No newsletter signup.
or book a 20-min scoping call first
We reply within one business day. Your data stays with us. No newsletter signup.
COMPLIANCE READY
Reports Mapped to Every Framework
Findings are written so your team can reference the report against each framework without translation work.
ISO 27001:2022
Annex A.8.8 management of technical vulnerabilities plus A.5.15-5.18 and A.8.2-8.5 access control validation.
SOC 2 Type I & II
CC6 logical access, CC7 system operations, CC8 change management evidence.
PCI DSS
Requirement 11.4 application penetration testing across cardholder data environments, including ecommerce penetration testing for online retail platforms.
FCA SYSC
SYSC 4.1.1R, 6.1.1R, 13 mapped to each finding for FCA-regulated firms.
UK GDPR
Article 32 effectiveness testing, customer-data security controls, ICO-acceptable evidence.
Cyber Essentials Plus
Direct certification through our IASME body status, single-vendor delivery.
PRICING
Transparent Zimbra Security Review Pricing
Pricing depends on the number of roles, integrations and environments in scope. See our pricing page for how we quote.
2 to 4 testing days
Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.
Get a fixed quote4 to 5 testing days
Multi-role SaaS, business application with payment integration. Around 8 to 12 working days from kickoff to report.
Get a fixed quote5 to 7 testing days
Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.
Get a fixed quoteSECTORS
Sectors We Test Zimbra For
Sector-specific scoping for regulated UK organisations.
Fintech & FCA-Regulated
FCA SYSC, Open Banking FAPI 1.0, PSD2 SCA, payment-flow scrutiny, KYC/AML testing.
Fintech sector pageSaaS Companies
SOC 2 Type I & II evidence, multi-tenant boundaries, role escalation, customer-tenant isolation.
SaaS sector pageLaw Firms
SRA Cyber Standard, privileged data, conveyancing fraud defence, partner-tier procurement.
Law firm sector pageHealthcare
NHS DTAC, DSP Toolkit v6, UK GDPR Article 32, EHR systems, telehealth platforms.
Healthcare sector pageInsurance
FCA / PRA Operational Resilience, cyber underwriting, claims data, broker portals.
Insurance sector pagePublic Sector
CCS / G-Cloud framework, NCSC-aligned, citizen-facing services, PSN-compliance scrutiny.
Public sector pageWHY EJN LABS
What You Get From Zimbra Security Review
Six concrete differentiators competitors don’t all match.
CREST-Certified Testers, Verifiable
Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.
24-Hour Startup, Where Required
From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.
Live Findings, Not 4-Week PDFs
Critical issues reported during testing through your client portal. Your team remediates while testing continues.
Audit-Ready Reports
Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).
Free Retests, Standard
Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.
UK-Based CREST Testers
Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.
FAQ
Frequently Asked
What access do you need to test our Zimbra deployment?
We need at least one standard user account and one delegated or global administrator account, plus details of any Classes of Service, distribution lists or mobile sync policies you want included. If preauth or single sign-on is configured, tell us during scoping so we can test it alongside standard login.
Will testing touch our live data?
We test whichever environment you give us access to. If that is production, we agree exclusions upfront, such as bulk deletes or mass distribution list changes, and we do not run destructive tests against real mailboxes without that agreement in writing.
How long does a Zimbra security review take?
A single Zimbra deployment sits in our 2-day single-platform scope, with a report typically landing around 5 working days after kickoff. A deployment with multiple domains, heavy delegated administration or a large distribution list structure moves into a wider scope with more testing days.
Do you test self-hosted Zimbra as well as hosted deployments?
Yes. We test Zimbra running on your own servers the same way as a deployment hosted by a managed provider, adjusting the self-hosted checks, such as admin console exposure and server-level access, to whichever hosting model you use.
What is out of scope for a single-platform Zimbra test?
Infrastructure underneath Zimbra, such as the host operating system, network or mail transfer agent configuration, is out of scope for this test and covered by our Linux server or cloud testing instead. A separate application that only happens to integrate with Zimbra, such as a connected identity provider, is scoped and quoted separately.
Do you need our source code or root server access?
No. Testing is black-box against the accounts and access you provide by default. A grey-box option, where we review relevant Class of Service settings, delegated admin rights and preauth configuration alongside testing, is available for faster or deeper coverage of specific findings.
Does Zimbra have a vendor security or disclosure policy we need to follow?
Zimbra publishes a responsible disclosure policy for researchers reporting vulnerabilities in the product itself, rather than a customer penetration-testing authorisation scheme, since a Zimbra deployment typically runs on infrastructure you or your hosting provider control rather than shared vendor infrastructure. We confirm current terms with you and, where relevant, your hosting provider during scoping, before testing starts.
Are your testers CREST certified?
Yes. Every Zimbra engagement is carried out by UK-based, CREST-certified testers, and your report and attestation letter are recognised by auditors and insurers accordingly.
20+ CREST-accredited testing services in one place
Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.
Get a fixed price for your Zimbra instance
Zimbra’s admin console, Class of Service and two-factor settings enforce exactly what your team configured, defaults or gaps included. We test which rights, policies and sync permissions actually apply to your accounts. CREST-certified testers, fixed price from £2,840 for a 2-day single-platform scope, quoted within 24 hours.



