Zimbra Collaboration Suite (ZCS) OnlyOffice Integration Path Traversal Remote Code Execution Vulnerability
Release Date: 21st September 2026
Impact : CRITICAL
TLP Rating: Clear 
The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.
This alert is relevant to Organizations and System/Network administrators that utilize the above product(s). This alert is intended to be understood by technical users and systems administrators.
What is it?
CVE-2026-93643 is a critical path traversal and missing authorization vulnerability (CWE-22 and CWE-863) in Zimbra Collaboration Suite (ZCS) when the OnlyOffice / Document Editing integration is available. An unauthenticated remote attacker who can reach an existing, supported public Briefcase document can abuse unsigned save fields to write files to arbitrary paths and then run commands as the zimbra system user. This amounts to taking over the mail server and every mailbox on it. CVSS score: 9.8 (Critical).
Zimbra was disclosed with three related stored cross-site scripting flaws in the same release cycle (CVE-2026-93641, CVE-2026-93642 and CVE-2026-93647, each CVSS 9.3), where a forged share notification or calendar message runs script in a signed-in user's session when they click or select it.
What are the systems affected?
The following Zimbra Collaboration Suite versions are affected where OnlyOffice / Document Editing is available:
ZCS versions below 10.1.21, per the CNA record (NVD analysis was still pending)
Not affected / patched version:
ZCS 10.1.21 or later. The sources do not state the fixed build explicitly, so confirm the exact fixed release for your version train against the Zimbra Security Advisories page.
What does this mean?
Successful exploitation may allow attackers to:
Write files to arbitrary locations on the Zimbra server and execute commands as the zimbra user, without credentials
Read, change or delete every user's mail, contacts and calendar, and use the server as a foothold into the internal network
With the related XSS flaws, steal mailbox data or act as a signed-in user after they click a forged share or calendar message
Mitigation process?
CERTVU recommends the following:
-
Update Zimbra
Upgrade to ZCS 10.1.21 or later, or the patch Zimbra lists for your release line, and confirm the exact build on the Zimbra Security Advisories page. -
Apply the workaround if patching is delayed
Disable the OnlyOffice / Document Editing integration, or revoke public Briefcase document shares, until the patch is installed. -
Restrict exposure
-
Hunt for compromise
Reference
- https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories
- https://nflo.tech/knowledge-base/2026-09-25-cve-2026-93643-en/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://nvd.nist.gov/vuln/detail/CVE-2026-93643
- Download advisory (English): Zimbra Collaboration Suite (ZCS) OnlyOffice Integration Path Traversal Remote Code Execution Vulnerability