Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-93643: Zimbra Collaboration Suite lets anyone write files and run code

CVE-2026-93643 · published 4 days ago
Summary

If Zimbra’s OnlyOffice document feature is enabled, a remote attacker who can view a public document can trick the system into writing files to any location and then run commands as the Zimbra service user. This could let the attacker take control of the server. Disable the OnlyOffice integration or apply the vendor's update, and restrict public document access.

What to do
  • Update zimbra zimbra collaboration suite (zcs) to version 10.1.21 or later.
Affected software
VendorProductAffected versions
zimbra zimbra collaboration suite (zcs) < 10.1.21
Original advisory text
Zimbra Collaboration Suite OnlyOffice Integration Path Traversal Leading to Remote Code Execution via Unauthenticated /downloadas Request
When OnlyOffice/Document Editing is available, an unauthenticated remote attacker with access to an existing supported public Briefcase document can abuse unsigned save fields to perform path-traversal writes and execute commands as zimbra.
Severity
9.8 Critical
CVSS 3.1: 9.8 (NVD)
Exploitation
EPSS <1%
Type
CWE-22Path Traversal
CWE-863Incorrect Authorization
Timeline
Published25 Sep 2026
Updated29 Sep 2026
First seen25 Sep 2026
Sources
CVE-2026-93643 · MITRE
Track software like this
Free during beta