Back

CRITICAL

Zimbra Collaboration Suite OnlyOffice Integration Path Traversal Leading to Remote Code Execution via Unauthenticated /downloadas Request

Published Sep 25, 2026

Description

When OnlyOffice/Document Editing is available, an unauthenticated remote attacker with access to an existing supported public Briefcase document can abuse unsigned save fields to perform path-traversal writes and execute commands as zimbra.

Affected products

Remediation

No remediation recorded yet.

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner rapid7
Published Sep 25, 2026
Updated Sep 26, 2026
Reserved Sep 18, 2026
CISA Vulnrichment
Updated Sep 25, 2026
NVD
Status Received
Modified Sep 25, 2026
Red Hat
Severity n/a
Public date n/a