Zimbra OnlyOffice CVE-2026-93643 Path Traversal in Save/Callback Endpoint
Detects incoming HTTP POST requests to the Zimbra OnlyOffice document handler containing path traversal sequences (e.g., '..'). This pattern is indicative of an attempt to exploit CVE-2026-93643 by manipulating document save or callback paths to access unauthorized files on the server.
Suricata

