Skip to main content
CRITICAL Vulnerabilities #Path Traversal#RCE#CISA KEV

CVE-2021-3199: ONLYOFFICE Docs RCE via Path Traversal

4 min read Runtime Rebel Intel
Primary source: cisa.gov

This article was written by a language model from the source above and was not reviewed by a human before publication. Verify anything operational against the original. Editorial policy

Key points
  • ONLYOFFICE Docs Server users face remote code execution risk due to confirmed active exploitation.
  • Affected systems include ONLYOFFICE Docs Server when configured with JWT and an image upload parameter.
  • Apply vendor mitigations and patches immediately, following CISA's BOD 26-04 guidance.

Advertisement

Overview of CVE-2021-3199 in ONLYOFFICE Docs Server

CISA has added CVE-2021-3199 to its Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation of a path traversal vulnerability in ONLYOFFICE Docs Server. This vulnerability, specifically present when JSON Web Token (JWT) is used and exploited via a /.. sequence within an image upload parameter, can lead to remote code execution (RCE). The inclusion in the KEV catalog underscores the immediate and severe risk this flaw poses, particularly for federal agencies mandated to remediate such vulnerabilities under CISA’s BOD 26-04 guidance, which has a federal remediation due date of 2026-10-11 for this issue, according to CISA.

Understanding ONLYOFFICE Docs Server Path Traversal Exploitation

The core of CVE-2021-3199 lies in a path traversal weakness, categorized as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory ‘Path Traversal’). This flaw specifically affects ONLYOFFICE Docs Server when configured with JSON Web Token (JWT) verification enabled. Attackers can leverage a specially crafted image upload request that includes a /.. sequence in the parameter. This sequence allows the attacker to manipulate the file path, causing the server to write a malicious file to an unintended, potentially sensitive, directory outside the intended upload location.

The critical aspect of this vulnerability is its potential for remote code execution. By uploading a malicious script or file to a web-accessible directory via path traversal, an attacker can then trigger the execution of their code on the server. This grants them significant control over the compromised system, potentially leading to data exfiltration, further network compromise, or the deployment of additional malware. The dependency on JWT being used and the specific image upload parameter indicates a targeted exploitation vector, yet its confirmed active exploitation means organizations cannot rely on obscurity as a defense.

Impact and Affected Systems

This vulnerability primarily impacts organizations utilizing ONLYOFFICE Docs Server, especially those that have implemented JWT for authentication or authorization mechanisms within their deployments. While the source material highlights the specific conditions for exploitation (JWT use, image upload parameter, /.. sequence), it emphasizes that CISA has confirmed active exploitation in the wild, making all such configurations immediate targets. The ability to achieve RCE means an attacker could gain full control over the server hosting ONLYOFFICE Docs, compromising the integrity, confidentiality, and availability of documents and potentially the entire host system.

Actionable Recommendations and Mitigations

Given the confirmed active exploitation and the severity of remote code execution, understanding how to mitigate ONLYOFFICE Docs RCE CVE-2021-3199 is a top priority for security teams. Immediate action is required to protect against this threat.

  • Apply Vendor Patches and Mitigations: The most critical step is to apply all available patches and follow vendor instructions for mitigating CVE-2021-3199. Organizations should consult ONLYOFFICE’s official security advisories for specific versions and patching procedures. If mitigations are unavailable, the source explicitly advises discontinuing product use as per BOD 26-04 guidance for cloud services.
  • Review JWT Configuration: Assess your ONLYOFFICE Docs Server deployment to determine if JSON Web Token (JWT) is currently in use. If JWT is not strictly necessary for your operational requirements, consider disabling it or reconfiguring it to minimize attack surface, if feasible and secure.
  • Monitor for Exploitation Attempts: Implement enhanced logging and monitoring for your ONLYOFFICE Docs Server instances. Specifically, look for unusual file uploads, attempts to access directories outside of normal operational paths (e.g., requests containing ../ sequences), and unexpected process execution or file modifications. This helps in detecting active exploitation or ONLYOFFICE Docs Server path traversal exploit attempts.
  • Network Segmentation: Isolate ONLYOFFICE Docs Server instances on your network where possible. This can limit an attacker’s lateral movement capabilities even if an initial compromise occurs via this vulnerability.
  • Adhere to CISA BOD 26-04: For federal agencies and organizations aligning with CISA’s directives, ensure compliance with BOD 26-04. This CISA KEV listing for CVE-2021-3199 remediation emphasizes prioritizing security updates based on risk and includes specific requirements for forensic triage in case of compromise. All stakeholders are responsible for evaluating asset internet exposure and adhering to these patching guidelines.

Related: CVE-2026-66384: JFrog Artifactory Path Traversal Exploit, CVE-2026-60137: WordPress Core SQL Injection to RCE — Patch Now

Advertisement

Advertisement