CVE-2026-93643 sits in the junction between Zimbra Collaboration’s web document editor and its server-side file handling. Zimbra is an enterprise communications and collaboration platform: organisations use it for mail, calendars, contacts, shared mailboxes, file storage and browser-based editing. That makes it a familiar choice for self-hosted and regulated deployments, particularly in government, education and finance.
The issue is not a generic requirement for a logged-in mailbox user. When OnlyOffice/Document Editing is available, an unauthenticated remote attacker who can reach an existing supported public Briefcase document can target its /downloadas request. The CVE record says attacker-controlled, unsigned save fields can be used to traverse directories during a filesystem write, then execute commands as the operating-system zimbra account. In practical terms, values intended to describe a document-save operation can escape their expected directory and direct a server process to write somewhere else.
Public documents become the starting point
The precondition matters, but it is not much comfort where users intentionally share editable office files. An attacker needs access to a suitable public Briefcase document; the published material does not say that any account, administrative access or prior authentication is required. Nor could research confirm whether OnlyOffice is enabled by default on every affected installation. Teams should therefore establish whether the integration is exposed and inventory public Briefcase content rather than assuming their normal login boundary protects this route.
The documented effect goes beyond overwriting an application file. Command execution as zimbra gives an intruder a foothold under the account that operates the collaboration service, with access determined by that account’s host permissions and surrounding configuration. The public record classifies the flaw as path traversal and incorrect authorization, but no patch diff or vulnerable source lines have been released. That means it is not currently possible to verify which save fields were trusted or whether the correction relies on signing, path validation, authorization checks, or all three.
Patch the conditional exposure now
Zimbra Collaboration 10.1.21, released September 24, 2026, is the fixed version; its release material includes updated OnlyOffice packages. The CNA record defines affected versions as 0 up to, but not including, 10.1.21, while Zimbra’s advisory table does not provide its own affected-version matrix and still shows the relevant CVE and score as TBD. That discrepancy is worth knowing: the release is clearly the remediation target, but older unsupported installations may also share the flaw.
Apply the normal Zimbra package update and patch process to reach 10.1.21, then review whether document editing must remain available and remove unnecessary public Briefcase documents. Where an immediate upgrade is impossible, restricting public document access and exposure to the affected editing path may reduce opportunity, but the published material does not provide a vendor-approved workaround. Review zimbra-account activity, application and web logs, and unexpected writes on the Zimbra host as part of incident triage.
No public exploitation evidence yet
As of September 26, 2026, CISA enrichment marks exploitation as none, and the CVE is not in CISA’s KEV catalogue. No incident, ransomware campaign or named threat actor has been tied to CVE-2026-93643. No public proof of concept or exploit code has surfaced either; private demonstrations or vendor-only material could not be confirmed.
This is a narrow but powerful chain: a publicly reachable collaboration document can become a write primitive and then code execution under the service account. Keep track of the systems that actually run Zimbra and its editing components; SecAlerts monitors an organisation’s actual software stack and alerts on new vulnerabilities affecting the products it runs.




