← Back to search

CVE-2026-93643

9.8 CRITICAL

Published 2026-09-25 · Updated 2026-09-29

AI risk analysis

Summary
This flaw allows unauthenticated attackers to perform path-traversal writes and execute commands as zimbra by abusing unsigned save fields in supported public Briefcase documents.
Exploitability
Exploitation requires access to an existing supported public Briefcase document and is moderately difficult due to the need for specific document manipulation.
Blast radius
If exploited, the attacker could gain elevated privileges as zimbra, potentially leading to full system compromise.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Disable the affected feature or restrict access to the named endpoint.
rceauth-bypassweb

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

When OnlyOffice/Document Editing is available, an unauthenticated remote attacker with access to an existing supported public Briefcase document can abuse unsigned save fields to perform path-traversal writes and execute commands as zimbra.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-22, CWE-863

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.