Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4508 articles · 223849 vulns · 37/41 feeds (7d)
← Back to list
9.8
CVE-2026-93643PATCHED
zimbra · zimbra collaboration suite (zcs)

Zimbra Collaboration Suite OnlyOffice Integration Path Traversal Leading to Remote Code Execution via Unauthenticated /downloadas Request

Description

When OnlyOffice/Document Editing is available, an unauthenticated remote attacker with access to an existing supported public Briefcase document can abuse unsigned save fields to perform path-traversal writes and execute commands as zimbra.

Affected Products

VendorProductVersions
zimbrazimbra collaboration suite (zcs)0

References

  • https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories(vendor-advisory)

Related News (1 articles)

Tier C
VulDB2d ago
CVE-2026-93643 | Zimbra Collaboration Suite up to 10.1.20 OnlyOffice path traversal
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.19.8 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
10.1.21
CWECWE-22, CWE-863
PublishedSep 25, 2026
Trending Score32
Source articles1
Independent1
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-93641
Zimbra Collaboration Suite Classic Web Client Stored Cross-Site Scripting via Forged Share Invitation
Trending: 24
CRITICALCVE-2026-93647
Zimbra Collaboration Suite Classic Web Client Stored Cross-Site Scripting via Crafted Calendar COUNTER Message From Address
Trending: 24
CRITICALCVE-2026-93642
Zimbra Collaboration Suite Modern Web Client Stored Cross-Site Scripting via Forged Share Invitation
Trending: 24
LOWCVE-2026-73574
CVE-2026-73574: In Zimbra Collaboration before 10.1.17, a local file inclusion (LFI) vulnerability exists in the Zimbra Classic Web Clie
MEDIUMCVE-2026-73572
CVE-2026-73572: In Zimbra Collaboration (ZCS) before 10.1.17, a stored cross-site scripting (XSS) vulnerability exists in the Zimbra Cla

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 25, 2026
Discovered by ZDM
Sep 25, 2026
Patch Available
Sep 26, 2026