ONLYOFFICE Docs Server Path Traversal Vulnerability

🚨SEVERITY: CRITICAL — CVSS 9.8Security Advisory

TL;DR 📌

  • ONLYOFFICE Docs contains a path traversal vulnerability that can occur when JWT is used, via a /.. sequence in an image upload parameter and could allow for remote code execution.
  • Highest CVSS: 9.8 (Critical).
  • Listed in CISA KEV (2026-10-08) — this is being exploited in the wild.
  • Fixed in 5.6.3 — upgrade to this release or later.
  • CVEs: CVE-2021-3199.

What it is

CVE-2021-3199 is a directory traversal flaw in ONLYOFFICE Document Server, reachable through the /upload endpoint. It affects deployments before version 5.6.3, specifically when JWT authentication is in use.

The flaw is triggered via a /.. sequence in an image upload parameter. An attacker who can reach the /upload endpoint and submit a crafted image upload request can write files outside the intended upload directory, which the advisory states can lead to remote code execution on the Document Server host.

The CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates this is exploitable over the network, with low attack complexity, no privileges required, and no user interaction — the full impact triad (confidentiality, integrity, availability) is rated high. This points to the upload handler being reachable without prior authentication to the application itself, though JWT is noted as a condition under which the traversal occurs.

This CVE is listed in CISA’s Known Exploited Vulnerabilities catalogue, added 8 October 2026, so it is known to be exploited in the wild.

What to do

  • Upgrade ONLYOFFICE Document Server to version 5.6.3 or later. This is the fixed release named in the advisory.
  • If you cannot patch immediately, restrict network access to the Document Server’s /upload endpoint — put it behind authentication at the network layer or limit it to trusted internal sources only.
  • Check whether JWT is enabled on your deployment, since the advisory specifically describes the traversal occurring under that condition; review your JWT configuration as part of remediation, not as a substitute for patching.
  • Given the KEV listing, treat this as a priority patch target: identify all Document Server instances in your estate, confirm their version, and patch or isolate any still on pre-5.6.3 builds.
  • After patching, review upload directories and server logs for unexpected files or /.. patterns in upload parameters that would indicate prior exploitation attempts.

For leadership 🧭

Executive summary. ONLYOFFICE Document Server versions before 5.6.3 contain a critical flaw that lets an attacker reach the /upload endpoint over the network and plant files leading to remote code execution, with no login or user interaction needed. It is listed in CISA’s Known Exploited Vulnerabilities catalogue, so any unpatched instance should be treated as an active target and fixed or isolated this week.

Why it matters:

  • The flaw sits in the /upload endpoint of Document Server and is triggered by a /.. sequence in an image upload parameter, giving attackers a direct path to write files outside the intended directory.
  • CVSS 9.8 with AV:N/AC:L/PR:N/UI:N means exploitation requires no credentials, no user clicks, and little skill, and the advisory states this can lead to remote code execution on the server host.
  • It is confirmed in CISA’s KEV catalogue, meaning this specific path traversal is being actively exploited rather than a theoretical risk.
  • Any exposed Document Server before 5.6.3 running with JWT enabled, the condition under which the traversal occurs, is a direct candidate for compromise and should be inventoried immediately.

Now / Next / Later:

  • Now: Identify every ONLYOFFICE Document Server instance in your estate, check its version, and confirm whether JWT authentication is enabled.
  • Next: Upgrade all instances to version 5.6.3 or later in the next change window; where immediate patching isn’t possible, restrict network access to the /upload endpoint to trusted internal sources only.
  • Later: Add Document Server to routine version-tracking and KEV-monitoring processes, and after patching review upload directories and server logs for unexpected files or /.. patterns indicating earlier exploitation attempts.

Source