# CVE-2021-3199: ONLYOFFICE Docs RCE via Path Traversal

> Actively exploited path traversal vulnerability [CVE-2021-3199] in ONLYOFFICE Docs Server enables remote code execution when JWT is used. Immediate patching is critical.

- Published: 2026-10-08T21:02:34.000Z
- Severity: critical
- Category: Vulnerabilities
- Tags: Path Traversal, RCE, CISA KEV, CVE-2021-3199, ONLYOFFICE Docs
- Author: Runtime Rebel Intel
- Primary source: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2021-3199
- Canonical: https://runtimerebel.com/blog/cve-2021-3199-onlyoffice-docs-rce-via-path-traversal

## Key points

- ONLYOFFICE Docs Server users face remote code execution risk due to confirmed active exploitation.
- Affected systems include ONLYOFFICE Docs Server when configured with JWT and an image upload parameter.
- Apply vendor mitigations and patches immediately, following CISA's BOD 26-04 guidance.

## Overview of [CVE](/glossary#cve)-2021-3199 in ONLYOFFICE Docs Server

[CISA](/glossary#cybersecurity-and-infrastructure-security-agency-cisa) has added [CVE-2021-3199](https://nvd.nist.gov/vuln/detail/CVE-2021-3199) to its Known Exploited Vulnerabilities ([KEV](/glossary#kev)) catalog, confirming active exploitation of a path traversal [vulnerability](/glossary#vulnerability) in ONLYOFFICE Docs Server. This vulnerability, specifically present when JSON Web Token (JWT) is used and exploited via a `/..` sequence within an image upload parameter, can lead to remote code execution ([RCE](/glossary#rce)). The inclusion in the KEV catalog underscores the immediate and severe risk this flaw poses, particularly for federal agencies mandated to remediate such vulnerabilities under CISA's BOD 26-04 guidance, which has a federal remediation due date of 2026-10-11 for this issue, according to [CISA](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2021-3199).

## Understanding ONLYOFFICE Docs Server Path Traversal Exploitation

The core of [CVE-2021-3199](https://nvd.nist.gov/vuln/detail/CVE-2021-3199) lies in a path traversal weakness, categorized as [CWE](/glossary#cwe)-22 (Improper Limitation of a Pathname to a Restricted Directory 'Path Traversal'). This flaw specifically affects ONLYOFFICE Docs Server when configured with JSON Web Token (JWT) verification enabled. Attackers can leverage a specially crafted image upload request that includes a `/..` sequence in the parameter. This sequence allows the attacker to manipulate the file path, causing the server to write a malicious file to an unintended, potentially sensitive, directory outside the intended upload location.

The critical aspect of this vulnerability is its potential for remote code execution. By uploading a malicious script or file to a web-accessible directory via path traversal, an attacker can then trigger the execution of their code on the server. This grants them significant control over the compromised system, potentially leading to [data exfiltration](/glossary#data-exfiltration), further network compromise, or the deployment of additional [malware](/glossary#malware). The dependency on JWT being used and the specific image upload parameter indicates a targeted exploitation vector, yet its confirmed active exploitation means organizations cannot rely on obscurity as a defense.

### Impact and Affected Systems

This vulnerability primarily impacts organizations utilizing ONLYOFFICE Docs Server, especially those that have implemented JWT for authentication or [authorization](/glossary#authorization) mechanisms within their deployments. While the source material highlights the specific conditions for exploitation (JWT use, image upload parameter, `/..` sequence), it emphasizes that CISA has confirmed active exploitation in the wild, making all such configurations immediate targets. The ability to achieve RCE means an attacker could gain full control over the server hosting ONLYOFFICE Docs, compromising the integrity, confidentiality, and availability of documents and potentially the entire host system.

## Actionable Recommendations and Mitigations

Given the confirmed active exploitation and the severity of remote code execution, understanding how to mitigate ONLYOFFICE Docs RCE [CVE-2021-3199](https://nvd.nist.gov/vuln/detail/CVE-2021-3199) is a top priority for security teams. Immediate action is required to protect against this threat.

*   **Apply Vendor Patches and Mitigations:** The most critical step is to apply all available patches and follow vendor instructions for mitigating [CVE-2021-3199](https://nvd.nist.gov/vuln/detail/CVE-2021-3199). Organizations should consult ONLYOFFICE's official security advisories for specific versions and patching procedures. If mitigations are unavailable, the source explicitly advises discontinuing product use as per BOD 26-04 guidance for cloud services.
*   **Review JWT Configuration:** Assess your ONLYOFFICE Docs Server deployment to determine if JSON Web Token (JWT) is currently in use. If JWT is not strictly necessary for your operational requirements, consider disabling it or reconfiguring it to minimize [attack surface](/glossary#attack-surface), if feasible and secure.
*   **Monitor for Exploitation Attempts:** Implement enhanced logging and monitoring for your ONLYOFFICE Docs Server instances. Specifically, look for unusual file uploads, attempts to access directories outside of normal operational paths (e.g., requests containing `../` sequences), and unexpected process execution or file modifications. This helps in detecting active exploitation or `ONLYOFFICE Docs Server path traversal exploit` attempts.
*   **[Network Segmentation](/glossary#network-segmentation):** Isolate ONLYOFFICE Docs Server instances on your network where possible. This can limit an attacker's [lateral movement](/glossary#lateral-movement) capabilities even if an initial compromise occurs via this vulnerability.
*   **Adhere to CISA BOD 26-04:** For federal agencies and organizations aligning with CISA's directives, ensure compliance with BOD 26-04. This CISA KEV listing for [CVE-2021-3199](https://nvd.nist.gov/vuln/detail/CVE-2021-3199) remediation emphasizes prioritizing security updates based on risk and includes specific requirements for forensic triage in case of compromise. All stakeholders are responsible for evaluating asset internet exposure and adhering to these patching guidelines.

**Related:** [CVE-2026-66384: JFrog Artifactory Path Traversal Exploit](/blog/cve-2026-66384-jfrog-artifactory-path-traversal-exploit), [CVE-2026-60137: WordPress Core SQL Injection to RCE — Patch Now](/blog/cve-2026-60137-wordpress-core-sql-injection-to-rce-patch-now)

---

AI-generated analysis from the primary source above; not human-reviewed before publication — verify anything operational against the original (https://runtimerebel.com/editorial). Quote with attribution and a link to the canonical URL: https://runtimerebel.com/blog/cve-2021-3199-onlyoffice-docs-rce-via-path-traversal
