Zimbra Collaboration Suite (ZCS) OnlyOffice Integration Path Traversal Remote Code Execution Vulnerability

Release Date: 21st September 2026

Impact : CRITICAL

TLP Rating: Clear

The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.

This alert is relevant to Organizations and System/Network administrators that utilize the above product(s). This alert is intended to be understood by technical users and systems administrators.

What is it?

CVE-2026-93643 is a critical path traversal and missing authorization vulnerability (CWE-22 and CWE-863) in Zimbra Collaboration Suite (ZCS) when the OnlyOffice / Document Editing integration is available. An unauthenticated remote attacker who can reach an existing, supported public Briefcase document can abuse unsigned save fields to write files to arbitrary paths and then run commands as the zimbra system user. This amounts to taking over the mail server and every mailbox on it. CVSS score: 9.8 (Critical).

Zimbra was disclosed with three related stored cross-site scripting flaws in the same release cycle (CVE-2026-93641, CVE-2026-93642 and CVE-2026-93647, each CVSS 9.3), where a forged share notification or calendar message runs script in a signed-in user's session when they click or select it.

Reference

  1. https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories
  2. https://nflo.tech/knowledge-base/2026-09-25-cve-2026-93643-en/
  3. https://www.cisa.gov/known-exploited-vulnerabilities-catalog
  4. https://nvd.nist.gov/vuln/detail/CVE-2026-93643