OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-93643

CRITICAL · CVSS 9.8 EPSS 0.96%

Source: NVD + CISA KEV + EPSS · Published 2026-09-25 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

An unauthenticated remote attacker can exploit a vulnerability in OnlyOffice/Document Editing within Office products to perform path-traversal writes, allowing them to execute commands with the privileges of the zimbra user. This critical vulnerability poses a significant risk to organizations using these products, particularly those that utilize public Briefcase documents. Organizations should prioritize patching this vulnerability to mitigate potential unauthorized access and command execution risks.

CVE
CVE-2026-93643
Severity
CRITICAL
CVSS
9.8
EPSS
0.96%
Office

Original NVD Description

When OnlyOffice/Document Editing is available, an unauthenticated remote attacker with access to an existing supported public Briefcase document can abuse unsigned save fields to perform path-traversal writes and execute commands as zimbra.