CISA has added CVE-2021-3199, a critical (CVSS 9.8) path traversal flaw in ONLYOFFICE Document Server that can lead to remote code execution, to its Known Exploited Vulnerabilities catalog and set a remediation deadline of October 11, 2026.
What Is It
CVE-2021-3199 is a directory traversal vulnerability (CWE-22) in the /upload endpoint of ONLYOFFICE Document Server. According to NVD, when JWT is in use, an attacker can supply a /.. sequence in an image upload parameter. This can lead to remote code execution. CISA lists it as the "ONLYOFFICE Docs Server Path Traversal Vulnerability." NVD first published the CVE on January 26, 2021.
Why It Matters
CISA added this CVE to the KEV catalog on October 8, 2026, which confirms active exploitation. CISA's SSVC assessment rates exploitation as active, automatable as yes, and technical impact as total.
NVD scores it 9.8 CRITICAL (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). That score means it can be exploited over the network with low complexity, with no privileges and no user interaction. NVD references also list public proof-of-concept exploit code. CISA marks this entry as requiring forensic triage. Known ransomware campaign use is listed as "Unknown."
CISA also notes that the flaw could affect an open-source component, third-party library, protocol, or proprietary implementation used by other products. That means the exposure may reach beyond standalone ONLYOFFICE deployments.
What's Vulnerable
- Product: ONLYOFFICE Document Server (ONLYOFFICE Docs)
- Affected versions: All versions before 5.6.3 (CPE
cpe:2.3:a:onlyoffice:document_server:*, version end excluding 5.6.3) - Condition: Deployments that use JWT
Patch Status
NVD identifies versions before 5.6.3 as vulnerable and references the ONLYOFFICE DocumentServer 5.6.3 changelog. CISA's required action is to apply mitigations according to the vendor's instructions, in line with BOD 26-04 (Prioritizing Security Updates Based on Risk) and CISA's Forensics Triage Requirements. For cloud services, organizations should follow the applicable BOD 26-04 guidance. If mitigations are unavailable, they should stop using the product.
Stakeholders are responsible for assessing each asset's internet exposure. Federal agencies must remediate by October 11, 2026.