ZeroDayAlert

CVE-2021-3199: ONLYOFFICE Docs Server Path Traversal Vulnerability

ONLYOFFICE Docs contains a path traversal vulnerability that can occur when JWT is used, via a /.. sequence in an image upload parameter and could allow for remote code execution.

ONLYOFFICE Docs Added to KEV 2026-10-08 Federal due 2026-10-11 Known ransomware use

Required action — quoted from CISA

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Where this comes from. The identifier, product, dates and required action above are copied verbatim from the CISA Known Exploited Vulnerabilities catalog. The action plan below is written by an AI agent from that record and published automatically. AssurePort has not independently tested this vulnerability and makes no claim about whether any specific system is affected.

Who is affected

ONLYOFFICE Docs is a collaborative document editing server product. The vulnerability affects deployments where JWT (JSON Web Token) authentication is in use, allowing an attacker to exploit a path traversal flaw during image upload. The record does not specify which versions of ONLYOFFICE Docs are vulnerable, nor does it detail whether self-hosted and cloud-hosted instances are equally affected.

How to check whether this touches you

  • Confirm whether you deploy or rely on ONLYOFFICE Docs in your environment, including any instances managed by third parties on your behalf.
  • Verify that JWT-based authentication is enabled in your ONLYOFFICE Docs configuration; if you use a different authentication method, your exposure profile may differ.
  • Establish whether your ONLYOFFICE Docs instance is reachable from the internet or only from trusted internal networks, as that determines attacker reach.
  • Check the running version against ONLYOFFICE's security advisories and patch history; version alone is not definitive, but it is the first signal to investigate.
  • Review upload logs and access logs covering the period since the vulnerability became public to identify whether the /.. image upload parameter has been probed or exploited.

What to do

  1. Obtain ONLYOFFICE's remediation guidance immediately—either a patched version number or a workaround—and evaluate whether your instance qualifies as critical infrastructure under BOD 26-04; if it does, prioritise patching within the federal remediation window.
  2. If a patch is available, apply it after testing in a non-production environment; document the patch version applied and the date of application.
  3. If no patch is available or patching is delayed, restrict network access to ONLYOFFICE Docs to authenticated internal users only; disable or remove public-facing upload endpoints if possible.
  4. Enable and review detailed logging for image upload requests, filtering for requests containing /../ or similar path traversal sequences; forward suspicious logs to your security team.
  5. If you cannot mitigate the risk through patching or access controls, follow BOD 26-04 guidance: either migrate to an alternative product or document a risk acceptance decision with appropriate approvals.

If you find you were exposed

Path traversal in file upload functionality typically leaves traces in access logs and potentially in filesystem changes. Review logs from before the patch date for requests to image upload endpoints that contain path traversal syntax; exploitation of this vulnerability could result in remote code execution, so check for unexpected process execution, new files, or outbound connections correlating with suspicious uploads. Log retention is often the bottleneck; if your logs have rolled over, focus on filesystem and process auditing to detect signs of persistent compromise.

Get these the morning they land.

One email, only when a vulnerability is newly confirmed as exploited — the CISA record plus our action plan. No more than one a day, and nothing on quiet days.

Knowing it exists is not the same as knowing you are exposed.

This page can tell you that CVE-2021-3199 is being exploited. It cannot tell you whether Docs is running somewhere of yours that is reachable. That question is what a scan answers.

Check your own surface →