Overview
CISA added CVE-2021-3199 to its Known Exploited Vulnerabilities (KEV) catalog on October 8, 2026 — confirming that a five-year-old, previously quiet bug is now being actively exploited in the wild. The flaw is a critical path traversal vulnerability (CVSS 9.8) in ONLYOFFICE Document Server (now branded ONLYOFFICE Docs) that, when JWT authentication is enabled, allows an unauthenticated attacker to escape the upload directory via a /.. sequence in an image upload parameter — and chain that escape into remote code execution.
The CVE itself was originally published back in January 2021. Its sudden KEV addition in 2026 is the real news here: it means defenders can no longer treat this as an old, patched-and-forgotten issue — unpatched ONLYOFFICE Document Server instances are confirmed targets today.
Technical Details
| Field | Value |
|---|---|
| CVE ID | CVE-2021-3199 |
| Severity | Critical (CVSS 9.8) |
| CWE | CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Attack Vector | Network |
| Privileges Required | None |
| User Interaction | None |
| Impact | Remote code execution via directory traversal |
| Affected Component | /upload image-upload endpoint (JWT-enabled configurations) |
| Affected Versions | ONLYOFFICE Document Server before 5.6.3 |
| Fixed Version | 5.6.3 |
How It Works
ONLYOFFICE Document Server exposes an /upload endpoint used to accept image uploads — for example, images embedded into documents being edited collaboratively. When JWT-based request signing is enabled (ONLYOFFICE's recommended hardening for API calls between the document editor and the server), the upload handler fails to properly sanitize the filename parameter supplied with the image.
An attacker can embed a /.. directory-traversal sequence inside that upload parameter. Instead of writing the uploaded file into the intended, sandboxed upload directory, the server resolves the path one or more levels above it — writing the attacker-controlled file wherever the traversal sequence points. Because ONLYOFFICE Document Server can execute or load files from various directories as part of its normal document-conversion and rendering pipeline, an attacker who can place a malicious file in the right location can get that file executed, achieving remote code execution with the privileges of the Document Server process. No authentication beyond reaching the JWT-protected endpoint is required, and no user interaction is needed — the attack is fully remote and automatable, which is consistent with public proof-of-concept exploit scripts (such as poc_uploadImageFile.py) already circulating.
Impact Assessment
Who Is At Risk
- Any organization running ONLYOFFICE Document Server (ONLYOFFICE Docs) before version 5.6.3, particularly self-hosted deployments reachable from the internet or from untrusted internal network segments
- Deployments that enabled JWT signing on the document server API — the specific configuration this flaw requires
- Integrations where ONLYOFFICE Document Server backs collaborative document editing for groupware, CMS, or file-sharing platforms (e.g. Nextcloud, ownCloud, custom document-management systems) and is not kept current with upstream patches
Potential Attack Chains
- Reconnaissance — Attacker identifies a reachable ONLYOFFICE Document Server instance, often fingerprinted via its exposed API or editor interface
- Crafted upload request — Attacker sends an image-upload request to
/uploadwith a/..traversal sequence embedded in the upload parameter - Path escape — The server resolves the traversal sequence and writes the attacker's file outside the intended upload sandbox, into a location reachable by the document-conversion/execution pipeline
- Code execution — The planted file is loaded or executed by the server, giving the attacker a foothold with Document Server process privileges
- Post-exploitation — From that foothold, an attacker can pivot to the underlying host, access documents processed by the server, or use the compromised instance as a pivot point into the wider network
Mitigation
Immediate Actions
- Upgrade ONLYOFFICE Document Server (ONLYOFFICE Docs) to 5.6.3 or later immediately. This has been the fix for five years; any instance still below that version has had an unpatched, now actively exploited RCE the entire time.
- CISA's KEV listing carries a required-action due date of October 11, 2026 for U.S. federal civilian agencies under Binding Operational Directive (BOD) 22-01/26-04 — apply the vendor's mitigation (patch to 5.6.3+) by that date. CISA's KEV entry also flags this CVE as requiring forensic triage per BOD 26-04, meaning agencies running vulnerable, internet-facing instances should assess for prior compromise, not just patch and move on.
- Non-federal organizations should treat the same deadline as a practical benchmark — if you are running a vulnerable version, prioritize patching this week, not in the next maintenance window.
- If immediate patching is not possible, restrict network access to the Document Server's
/uploadendpoint to trusted callers only as a stopgap.
Detection Opportunities
- Review Document Server access logs for upload requests containing
/..or URL-encoded traversal sequences (%2e%2e%2f) in filename or path parameters - Look for unexpected files appearing outside the configured upload directory, especially in locations the conversion/rendering pipeline can reach
- Monitor for anomalous child processes spawned by the Document Server service — a strong indicator of successful code execution
- Check for the presence of known PoC artifact names or patterns associated with public exploit scripts targeting this CVE
Defence-in-Depth
- Keep ONLYOFFICE Document Server on a current, supported release and track vendor changelogs for security-relevant fixes
- Run the Document Server process with the least privilege necessary, and isolate it (containers, dedicated service accounts, restricted filesystem access) so a compromised process cannot easily reach sensitive data or pivot further
- Apply network segmentation so the upload API is not directly internet-exposed unless strictly required
- Maintain an inventory of self-hosted document-collaboration services (ONLYOFFICE and otherwise) so KEV additions like this one can be matched against your environment quickly
Discovery & Disclosure
CVE-2021-3199 was originally published on January 26, 2021, with ONLYOFFICE shipping the fix in Document Server 5.6.3. For nearly five years it sat as a patched, historical CVE with no confirmed in-the-wild exploitation.
That changed on October 8, 2026, when CISA added CVE-2021-3199 to its Known Exploited Vulnerabilities catalog, confirming active exploitation and assigning a federal remediation due date of October 11, 2026. This pattern — an old, patched vulnerability resurfacing as a live KEV entry years later — typically means attackers have found a durable population of never-patched, internet-facing instances still worth targeting. Any organization that assumed this bug was "too old to matter" should treat the KEV addition as confirmation that unpatched instances remain exploitable targets today.