External risk intelligence

OnlyOffice Path Traversal Allows Remote Command Execution

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-93643

The vulnerability affects Zimbra, an enterprise collaboration suite frequently deployed as a public-facing email and document management gateway. Because it involves an unauthenticated remote execution vector in a product designed to be accessible via the internet for remote user access, it is considered a public-facing service by design.

Path Traversal

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This critical vulnerability in OnlyOffice/Document Editing, a component of Zimbra, allows unauthenticated remote attackers to execute commands as the zimbra user. The issue arises from how unsigned save fields are handled, potentially enabling unauthorized file writes and command execution. At a high level, this could compromise the integrity and availability of the affected system.

  • Unauthenticated attackers can run commands remotely.
  • It affects a widely used enterprise collaboration tool.
  • Focus on confirming relevance and exposure to Zimbra.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker could exploit this by accessing a publicly shared document. They can then manipulate specific fields to write to unintended locations on the server, potentially leading to command execution with elevated privileges.

  • No authentication required.
  • Abuse unsigned save fields.
  • Execute commands as zimbra.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to execute commands on the server when a supported public Briefcase document is accessible. This is possible by exploiting unsigned save fields to perform path-traversal writes, potentially leading to unauthorized command execution with elevated privileges.

  • System data and service behavior.
  • Abuse of unsigned save fields.
  • Unauthorized command execution.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability in OnlyOffice/Document Editing allows unauthenticated remote attackers to execute commands as the `zimbra` user by exploiting unsigned save fields for path-traversal writes. Initial triage should focus on identifying all instances of the affected OnlyOffice/Document Editing component within your Zimbra environment, assessing their exposure and criticality, and confirming the responsible team for remediation. This approach ensures that immediate attention is directed to the most vulnerable and impactful systems.

  • Identify affected component owners.
  • Verify external accessibility and business impact.
  • Plan remediation based on exposure risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Zimbra and the OnlyOffice component?

Zimbra is an enterprise collaboration suite used by organizations to manage email, calendars, and shared document workflows. OnlyOffice is an integrated document editing component within Zimbra that allows users to create and collaborate on files directly within the platform's Briefcase feature.

What does CWE-22 and CWE-863 mean for CVE-2026-93643?

These codes identify the nature of the security flaw. CWE-22 refers to Path Traversal, where an attacker manipulates file paths to access or write to unauthorized locations. CWE-863 refers to Incorrect Authorization, meaning the system fails to properly verify if a user has permission to perform specific save actions. Together, they allow an attacker to bypass security checks and write files where they shouldn't.

How does an attacker trigger this vulnerability?

The attack requires access to an existing, supported public document within the Zimbra Briefcase. The attacker does not need authentication to the system. The bug is not triggered by simply viewing a document; it specifically requires the manipulation of unsigned save fields to force the system to write data to unintended paths, eventually leading to command execution.

Is my Zimbra environment at risk?

According to Halo Surface Signal, this vulnerability is very likely to affect your infrastructure because Zimbra is frequently deployed as a public-facing gateway for remote access. If your installation allows external users to interact with document services, it should be considered internet-facing and potentially reachable by remote actors.

Do I need to take immediate action?

Yes. Start by identifying all systems running the OnlyOffice/Document Editing component within your environment. Once identified, confirm which instances are accessible externally and evaluate their business criticality. Coordinate with your team to prioritize these assets for updates as you prepare for official remediation steps.

References