Impact
An unauthenticated attacker can exploit a path‑traversal flaw in Zimbra Collaboration Suite’s OnlyOffice integration. By sending unsigned save fields within an existing public Briefcase document, the attacker can write arbitrary files to the server’s file system and execute arbitrary system commands as the zimbra user. This provides full remote code execution with the privileges of the zimbra account and is a critical security issue, reflected in the CVSS score of 9.8.
Affected Systems
The vulnerability affects Zimbra Collaboration Suite (ZCS). No specific affected version information is provided in the CNA data; therefore it is assumed that any version currently using the OnlyOffice integration may be at risk unless a vendor patch is applied.
Risk and Exploitability
The CVSS score of 9.8 indicates a severe level of critical risk. Although the EPSS score is not available, the unauthenticated nature of the attack and the ability to gain code execution likely make exploitation highly desirable for adversaries. The vulnerability is not currently listed in CISA’s KEV catalog, but its confirmed impact and lack of authentication requirements mean it remains a high‑priority threat. The attack vector is inferred to be an unauthenticated HTTP request to the /downloadas endpoint that interacts with OnlyOffice’s document editing functionality, allowing arbitrary file writes and command execution.
OpenCVE Enrichment