CVE-2026-93643: Zimbra Collaboration Suite OnlyOffice Integration Path Traversal Leading to Remote Code Execution via Unauthenticated /downloadas Request
CVE-2026-93643 - zimbra collaboration suite (zcs) If Zimbra’s OnlyOffice document feature is enabled, a remote attacker who can view a public document can trick the system into writing files to any location and then… Too many irrelevant or confusing CVEs? com #zimbra #CVE #infosec When OnlyOffice/Document Editing is available, an unauthenticated remote attacker with access to an existing supported public Briefcase document can abuse.