CRITICAL 9.8 CVE-2026-93643 Published 25 Sept 2026

Zimbra OnlyOffice Path Traversal Command Execution Vulnerability

Worried this affects your website?

Zimbra with OnlyOffice/Document Editing enabled is affected by a path-traversal vulnerability that can lead to command execution.

An unauthenticated remote attacker with access to an existing supported public Briefcase document can abuse unsigned save fields to perform path-traversal writes and execute commands as zimbra.

  • Affected condition: OnlyOffice/Document Editing is available.
  • Precondition: attacker has access to an existing supported public Briefcase document.
  • Impact: path-traversal writes and command execution as zimbra.

Reference: CVE-2026-93643 on NVD

← Back to Security News