Skip to finding
important · Edge

A public Zimbra Briefcase document can become unauthenticated command execution as the zimbra account.

Affects

Zimbra Collaboration Suite mail and collaboration servers with OnlyOffice or Document Editing available.

An anonymous caller needs the URL of an existing supported public document on a server with OnlyOffice or Document Editing enabled.

Detail and 3 sources

Unsigned save fields permit path-traversal writes outside the document location, producing command execution under the zimbra service identity.

Zimbra has published a fix.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Tuesday, September 29, 2026