ONLYOFFICE Docs path traversal CVE-2021-3199 added to CISA KEV
At a glance
| Severity | CRITICAL |
|---|---|
| CVSS | CVE-2021-3199: 9.8 |
| EPSS (30-day exploit probability) | CVE-2021-3199: 8.2% |
| In CISA KEV (exploited) | Yes, due 2026-10-11 |
| Vendor | ONLYOFFICE |
| CVE IDs | CVE-2021-3199 |
CISA added CVE-2021-3199, a path traversal flaw in ONLYOFFICE Docs (Document Server), to its Known Exploited Vulnerabilities (KEV) catalog on 8 October 2026. The bug can lead to remote code execution on servers running versions before 5.6.3 where JWT is enabled, and federal agencies have until 11 October 2026 to apply mitigations.
Anyone running a self-hosted ONLYOFFICE Document Server should check the version now. The KEV listing is CISA’s confirmation that the flaw is being exploited, even though the entry does not describe who is attacking or how.
What happened with the ONLYOFFICE Docs vulnerability
NVD describes the issue as directory traversal in the /upload endpoint. An attacker supplies a /.. sequence in an image upload parameter, which lets the file land outside the intended folder and can result in code execution. The condition applies when JWT is used.
The flaw was published in January 2021, so this is an old bug that has now been confirmed as exploited. Details of the exploitation activity, including attacker identity and victims, have not been disclosed. CISA lists known ransomware campaign use as Unknown.
Am I affected by CVE-2021-3199?
- Affected: ONLYOFFICE Document Server earlier than 5.6.3 (per NVD).
- Not affected by this specific issue: 5.6.3 and later, which the project changelog references for the fix.
- Unknown: whether vendor-hosted or bundled deployments (for example inside other products that embed Document Server) carry an old build. Check the embedded version, not just the product name.
Technical details
| Item | Value |
|---|---|
| CVE | CVE-2021-3199 |
| Weakness | CWE-22 (path traversal) |
| CVSS 3.1 | 9.8 Critical, CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Attack vector | Network, no privileges, no user interaction |
| CISA KEV added | 2026-10-08 |
| KEV due date | 2026-10-11 |
| EPSS | 0.08215 (about 8.2% estimated chance of exploitation activity) |
| Ransomware use | Unknown |
The vector means the server can be attacked remotely without logging in, which is why the score is so high. Public proof-of-concept scripts for the upload flaw are listed among the NVD references, which lowers the effort needed to try it.
Why this matters
Analysis, not new facts from the source. Document servers are often placed behind a reverse proxy so staff can edit files from outside the network. If your instance is internet-facing and old, treat it as exposed to a pre-authentication code execution bug with public exploit code. A KEV listing combined with a three-day deadline puts this in the patch-within-hours category for internet-exposed hosts.
The low EPSS score should not reassure you: it is a statistical estimate, while KEV reflects observed exploitation.
How to detect exploitation of CVE-2021-3199
No indicators of compromise have been published. The following hunting ideas follow from the vulnerability description:
- Search web server and proxy logs for requests to
/uploadcontaining..or encoded variants in the image parameter. - Look for files written outside the Document Server upload directories, and for new executable or script files in web-accessible paths.
- Review child processes spawned by the Document Server service and any outbound connections from the host that are new.
CISA’s required action also references its forensics triage requirements, so preserve logs and disk evidence before cleaning up a host that looks suspicious.
What to do: fix CVE-2021-3199
- Inventory every ONLYOFFICE Document Server, including copies embedded in other platforms, and record the version.
- Upgrade anything earlier than 5.6.3 to a current release.
- If you cannot upgrade immediately, remove internet exposure by restricting access at the firewall or proxy, as CISA directs following vendor mitigations or discontinuing the product when mitigations are unavailable.
- Hunt for signs of prior compromise using the ideas above, starting with internet-facing hosts.
- Tell the owners of dependent file-sharing or collaboration platforms so they can confirm their own embedded versions.
Sources
- NVD: CVE-2021-3199
- CISA KEV catalog entry for CVE-2021-3199
- ONLYOFFICE DocumentServer changelog 5.6.3
