When OnlyOffice/Document Editing is available, an unauthenticated remote attacker with access to an existing supported public Briefcase document can abuse unsigned save fields to perform path-traversal writes and execute commands as zimbra.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories |
|
History
Fri, 25 Sep 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | When OnlyOffice/Document Editing is available, an unauthenticated remote attacker with access to an existing supported public Briefcase document can abuse unsigned save fields to perform path-traversal writes and execute commands as zimbra. | |
| Title | Zimbra Collaboration Suite OnlyOffice Integration Path Traversal Leading to Remote Code Execution via Unauthenticated /downloadas Request | |
| Weaknesses | CWE-22 CWE-863 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: rapid7
Published:
Updated: 2026-09-25T16:10:13.016Z
Reserved: 2026-09-18T12:22:38.559Z
Link: CVE-2026-93643
No data.
Status : Received
Published: 2026-09-25T14:17:23.550
Modified: 2026-09-25T17:17:19.860
Link: CVE-2026-93643
No data.
OpenCVE Enrichment
Updated: 2026-09-25T17:15:15Z