Skip to content
Rush Commerce
Software & Dev3 min read

Zimbra CVE-2026-93643: unauth RCE, patch to 10.1.21

A CVSS 9.8 path traversal in Zimbra's OnlyOffice document editing gives unauthenticated attackers command execution as zimbra. Patch or disable the integration.

The feature that turns your mail server into a document editor is the feature that just handed it away. Zimbra CVE-2026-93643 is a CVSS 9.8 path traversal in the OnlyOffice document editing integration: an unauthenticated attacker who can reach a public Briefcase document abuses unsigned save fields to write files outside the intended directory and run commands as the zimbra user. NVD published it on September 25. The fix is ZCS 10.1.21.

What actually happened

Per NVD, the flaw sits in how Zimbra handles save requests coming back from OnlyOffice. Those requests carry fields that are not signature-checked, so path traversal sequences survive validation and the write lands wherever the attacker points it. Write to the right place as the zimbra service account and you have command execution on the mail host. No credentials, no session, no user interaction — the prerequisites are that OnlyOffice document editing is enabled and that a supported public Briefcase document exists to attach the request to.

Zimbra's own security advisories list 10.1.21 as the release carrying OnlyOffice integration security fixes, alongside a Classic Web Client stored XSS and WebDAV authentication changes. Anything earlier than 10.1.21 is affected.

This is the same product family that got mass-exploited earlier this year, months after a patch had shipped, because hundreds of organizations never applied it. Zimbra stays a target for structural reasons: it is self-hosted, it sits on the open internet by design, and it holds every invoice, contract, and password reset your business has ever sent.

Why an unauthenticated RCE in your mail server matters

Mail host compromise is total compromise. The zimbra account owns the mail store. An attacker there reads every mailbox, forwards mail silently, and uses your own domain to phish your customers with real thread history. There is no clean "we patched it, we're fine" — after the patch you check for forwarding rules, new delegates, unexpected filters, and fresh SSH keys.

Optional integrations are attack surface you chose. OnlyOffice editing inside webmail is a convenience for maybe five percent of your users. If you cannot patch to 10.1.21 today, disable document editing and take the convenience hit. We run the same test on every feature toggle in a client's stack: who actually uses this, and what does leaving it on cost us?

Self-hosted collaboration needs a patch SLA in writing. If you run your own Zimbra, Nextcloud, or GitLab to keep data in your hands — a good reason — the trade is that critical patching is your job, on a clock. Ours is 24 hours for CVSS 9-plus on anything internet-facing, and the clock starts at vendor publication, not at the point someone notices.

Do not wait for a KEV listing. A working unauthenticated write primitive on a widely deployed mail platform gets scanned for within days. Exploitation status moves faster than any catalog updates.

Key takeaways

  • CVE-2026-93643 is a CVSS 9.8 path traversal in Zimbra's OnlyOffice document editing, published by NVD on September 25
  • Unauthenticated attackers abuse unsigned save fields to write arbitrary files and run commands as the zimbra account
  • Versions before ZCS 10.1.21 are affected; 10.1.21 carries the OnlyOffice fix plus a Classic client XSS fix
  • Exploitation requires OnlyOffice editing enabled and a reachable public Briefcase document
  • If you cannot patch now, disable the document editing integration as a stopgap
  • After patching, audit forwarding rules, delegates, mail filters, and SSH keys on the host

We treat patch windows as a service level, not a chore. Rush Commerce inventories what you self-host, strips the integrations nobody uses, and puts a real clock on critical CVEs so a Friday advisory does not become a Monday breach. See how we manage the stack, or have us audit your internet-facing systems.

Sources: NVD, Zimbra Security Advisories.

  • #zimbra
  • #cve-2026-93643
  • #patch-management
  • #rce
  • #email-security
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.