CVE-2026-93643

9.8

Zimbra · Collaboration Suite (ZCS)

An unauthenticated remote attacker can exploit unsigned save fields in the OnlyOffice document editing feature to perform path traversal and execute arbitrary commands as the zimbra user.

Executive summary

Zimbra Collaboration Suite is vulnerable to unauthenticated remote code execution via a path traversal flaw in the OnlyOffice document editing component, posing a critical risk to system integrity.

Vulnerability

This vulnerability involves a path traversal flaw (CWE-22) and incorrect authorization (CWE-863) within the OnlyOffice integration. An unauthenticated attacker can leverage access to a public Briefcase document to manipulate unsigned save parameters, leading to unauthorized file writes and arbitrary code execution.

Business impact

The potential for unauthenticated remote code execution grants an attacker full control over the affected Zimbra server, which typically houses sensitive organizational communications and credentials. Given the CVSS score of 9.8, this vulnerability represents a critical threat that could lead to complete data exfiltration, service disruption, and lateral movement within the corporate network.

Remediation

Immediate Action: Update Zimbra Collaboration Suite (ZCS) to version 10.1.21 or later immediately to apply the vendor-provided patch.

Proactive Monitoring: Monitor server logs for unusual file write operations, particularly those directed toward non-standard directories or binary paths, and inspect traffic patterns associated with the Briefcase module.

Compensating Controls: If patching cannot be performed immediately, disable the OnlyOffice/Document Editing feature within the Zimbra configuration to eliminate the vulnerable attack vector.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Due to the critical severity and the potential for total system compromise, organizations should prioritize the deployment of the 10.1.21 update. Failure to remediate this vulnerability leaves the environment exposed to unauthenticated attackers who can gain persistent access to the underlying infrastructure. If immediate patching is not feasible, the OnlyOffice component must be disabled to prevent exploitation.

More Zimbra CVEs

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief critical section

Sources

Originally found and disclosed by Jonah Burgess (CryptoCat), Senior Security Researcher, Rapid7, per the CVE Program record.