CVE-2026-93643: Zimbra Collaboration Suite OnlyOffice Integration Path Traversal Leading to Remote Code Execution via Unauthenticated /downloadas Request

CVE-2026-93643 - zimbra collaboration suite (zcs) If Zimbra’s OnlyOffice document feature is enabled, a remote attacker who can view a public document can trick the system into writing files to any location and then… Too many irrelevant or confusing CVEs? com #zimbra #CVE #infosec When OnlyOffice/Document Editing is available, an unauthenticated remote attacker with access to an existing supported public Briefcase document can abuse.

2 reportsother

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

CVE-2026-93643: Zimbra Collaboration Suite OnlyOffice Integration Path Traversal Leading to Remote Code Execution via Unauthenticated /downloadas Request

stream:bsky-jetstreamother3d ago kagi ↗

CVE-2026-93643 - zimbra collaboration suite (zcs) If Zimbra’s OnlyOffice document feature is enabled, a remote attacker who can view a public document can trick the system into writing files to any location and then… Too many irrelevant or confusing CVEs? Use stackflag.com #zimbra #CVE #infosec When OnlyOffice/Document Editing is available, an unauthenticated remote attacker with access to an exis

CVE-2026-93641: Zimbra Collaboration Suite Classic Web Client Stored Cross-Site Scripting via Forged Share Invitation

stream:bsky-jetstreamother3d ago kagi ↗

CVE-2026-93641 - zimbra collaboration suite (zcs) A malicious sender can create a fake share invitation that, when a logged‑in Zimbra Classic user clicks "Accept Share," runs hidden code in the user's browser. This… Too many irrelevant or confusing CVEs? Use stackflag.com #zimbra #CVE #infosec An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra