• PATCH AVAILABLE

CVE-2026-93643: pre-auth remote code execution in Zimbra Zimbra Collaboration Suite (ZCS)

An unauthenticated attacker can cause a Zimbra Collaboration Suite server to accept crafted writes that escape intended directories and lead to code execution as the zimbra user. CVE-2026-93643 targets installations where the OnlyOffice/Document Editing integration and a publicly available Briefcase document are present. A network-accessible server and access to a supported public Briefcase document are sufficient; no account or user interaction is required. The flaw impacts ZCS 10.x releases prior to 10.1.21.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
9.8CRITICAL
EPSS
0.0096
CWE
CWE-22
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: this is a pre-auth RCE requiring no login; install the 10.1.21 update promptly or block public Briefcase and OnlyOffice document editing exposure while you patch.

What is CVE-2026-93643?

An unauthenticated attacker can cause a Zimbra Collaboration Suite server to accept crafted writes that escape intended directories and lead to code execution as the zimbra user. CVE-2026-93643 targets installations where the OnlyOffice/Document Editing integration and a publicly available Briefcase document are present. A network-accessible server and access to a supported public Briefcase document are sufficient; no account or user interaction is required. The flaw impacts ZCS 10.x releases prior to 10.1.21. The weakness is classified as CWE-22 (Path Traversal).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Zimbra Zimbra Collaboration Suite (ZCS) are affected?

BRANCHAFFECTEDFIXED
10.xbefore 10.1.2110.1.21

Is CVE-2026-93643 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-93643

  1. Upgrade Zimbra Collaboration Suite 10.x to 10.1.21.
  2. If immediate upgrade is not possible, disable or restrict OnlyOffice/Document Editing and public Briefcase document access to trusted networks.
  3. Monitor Zimbra server logs for anomalous file writes and for unexpected processes running as the zimbra user.
  4. Follow any additional mitigations published by Zimbra.

Frequently asked questions

Is CVE-2026-93643 being actively exploited?

There are no public reports of exploitation of CVE-2026-93643 as of 2026-09-29.

Which Zimbra Collaboration Suite (ZCS) versions are affected by CVE-2026-93643?

Zimbra Collaboration Suite 10.x releases before 10.1.21 are affected by CVE-2026-93643.

Is there a patch for CVE-2026-93643?

Yes, Zimbra addressed the vulnerability in version 10.1.21.

Does CVE-2026-93643 require authentication?

No; the vulnerability can be exploited without authentication when OnlyOffice/Document Editing is enabled and a supported public Briefcase document is reachable.

References