Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
When OnlyOffice/Document Editing is available, an unauthenticated remote attacker with access to an existing supported public Briefcase document can abuse unsigned save fields to perform path-traversal writes and execute commands as zimbra.
An unauthenticated attacker over the network with access to a public Briefcase document can execute arbitrary commands as the zimbra user, read sensitive files, and modify system files.
There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.
Patch is available. Update Zimbra Collaboration Suite (ZCS) to version 10.1.21 or later.
Immediately update Zimbra Collaboration Suite to version 10.1.21 or later. Restrict access to public Briefcase documents if OnlyOffice/Document Editing is enabled. Consider disabling OnlyOffice/Document Editing functionality if it is not required until patching can be applied.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Feedly found the first article mentioning CVE-2026-93643 . See article
NVD published the first details for CVE-2026-93643
A CVSS base score of 9.8 has been assigned.
A critical vulnerability with a CVSS score of 9.8 allows unauthenticated remote command execution in the OnlyOffice/Document Editing component when integrated with Zimbra, exploiting insufficient input validation and signature enforcement. Currently, there are no public proof-of-concept exploits available, but organizations must prioritize applying the official vendor patch as soon as it becomes available. The vulnerability is not listed in CISA KEV, and remediation efforts are still under review. See article
GitHub Advisories released a security advisory .
[GHSA-4g2j-34p9-p684] When OnlyOffice/Document Editing is available, an unauthenticated remote attacke
CVE-2026-93643: Zimbra OnlyOffice Unauthenticated Path Traversal RCE as Zimbra User
CVE-2026-62262: Piwigo Unauthenticated SQL Injection Exposes Database Information
CVE-2026-93647: Zimbra Classic Stored XSS via Malicious Calendar Message Enables Mailbox Takeover
Critical vulnerabilities in Zimbra Collaboration Suite
Critical Zimbra RCE and XSS Flaws Enable Mailbox Takeover and Enterprise Record Manipulation
Be the first to know critical vulnerabilities
Collect, analyze, and vulnerability reports faster using AI
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
