Junglewise Threat Intelligence

CVE-2026-93643: When OnlyOffice/Document Editing is available, an unauthenticated remote attacker with access to an existing supported public Briefcase docu

CVE-2026-93643 · Severity: critical · CVSS 9.8 · Published 2026-09-25

Executive brief

When OnlyOffice/Document Editing is available, an unauthenticated remote attacker with access to an existing supported public Briefcase document can abuse unsigned save fields to perform path-traversal writes and execute commands as zimbra.

References