CVE-2021-3199

CRITICAL CISA KEV Pub 22/01 Upd 09/10

Overview

This vulnerability is a directory traversal flaw rooted in insufficient validation of file path inputs during image uploads. The affected component is the /upload endpoint in ONLYOFFICE Document Server versions prior to 5.6.3 when JSON Web Tokens (JWT) are used for authentication. The flaw allows traversal sequences (e.g., /..) to manipulate file paths, enabling unauthorized access to the file system and execution of arbitrary code on the server.

Vulnerability Description

Directory traversal with remote code execution can occur in /upload in ONLYOFFICE Document Server before 5.6.3, when JWT is used, via a /.. sequence in an image upload parameter.

Impact

An unauthenticated attacker can exploit this vulnerability to upload malicious files outside the intended directory, resulting in remote code execution on the server hosting ONLYOFFICE Document Server. This enables full system compromise, including unauthorized access to sensitive data and potential lateral movement within the network. The attack requires no user interaction or valid credentials, increasing the risk of automated exploitation and widespread impact on affected deployments.

Solution

Upgrade ONLYOFFICE Document Server to version 5.6.3 or later, where the directory traversal vulnerability in the /upload endpoint has been addressed as documented in the official changelog (https://github.com/ONLYOFFICE/DocumentServer/blob/903fe5ab7a275bd69c3c3346af2d21cf87ebeabf/CHANGELOG.md#563). No specific workarounds are provided; applying the vendor patch is required to remediate the issue effectively.

EPSS vs KEV Prediction — Evolution (30 days)

Affected Products (1)

Vendor Product Version CPE
onlyoffice Onlyoffice Document Server All cpe:2.3:a:onlyoffice:document_server:*:*:*:*:*:*:*:*

Exploits

No exploits found for this CVE.

Exploited in Wild CONFIRMED
Ransomware NOT ASSOCIATED
Attacker Interest VERY HIGH
Sightings Extensive activity

Threat Feed

4 events
2026-10-09
Threat Sensor Sighting — Extensive activity

Sighting activity recorded

2026-10-08
Threat Sensor Sighting — Some sightings

Sighting activity recorded

2026-10-08
Added to CISA KEV Catalog

CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog

Detected as Exploited in the Wild (233 sightings)

Active exploitation confirmed with 233 sighting(s)

Likely Kill Chain

Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.

Applicable Out of scope
Initial Access
TA0001
Execution
TA0002
Persistence
TA0003
Priv. Escalation
TA0004
Defense Evasion
TA0005
Credential Access
TA0006
Lateral Movement
TA0008
Collection
TA0009
Impact
TA0040

Highlighted stages are those attackers typically reach when exploiting this CVE. Heuristic based on CWE families — refined by ML classifier when available.

Attack Vectors ML

Path Traversal
100% path_traversal
Remote Code Execution
52% rce
File Upload Vulnerabilities
49% file_upload

MITRE ATT&CK Techniques (0)

ATT&CK techniques pending

Techniques are derived from this CVE's kill chains once ML classification completes.

CAPEC Attack Patterns ML

ID Name ML Conf. Likelihood Severity Link
CAPEC-126 Path Traversal
40%
High Very High
CAPEC-64 Using Slashes and URL Encoding Combined to Bypass Validation Logic
37%
High High
CAPEC-79 Using Slashes in Alternate Encoding
37%
High High
CAPEC-78 Using Escaped Slashes in Alternate Encoding
35%
High High
CAPEC-76 Manipulating Web Input to File System Calls
32%
High Very High

Red Team Playbook

AtomicRedTeam integration in progress

Executable commands will be auto-mapped to each ATT&CK technique of this CVE.

Detection & Response Rules

No detection or response rules found for this CVE.

No news articles found for this CVE.

References (5)

Title Tags URL
nvd.nist.gov
NVD reference
https://nvd.nist.gov/vuln/detail/CVE-2021-3199
github.com
GitHub CVE x_refsource_CONFIRM
https://github.com/ONLYOFFICE/DocumentServer/blob/903fe5ab7a275bd69c3c3346af2d21cf87ebeabf/CHANGELOG.md#563
github.com
GitHub CVE x_refsource_MISC
https://github.com/nola-milkin/poc_exploits/blob/master/CVE-2021-3199/poc_uploadImageFile.py
github.com
GitHub CVE x_refsource_MISC
https://github.com/moehw/poc_exploits/tree/master/CVE-2021-3199/poc_uploadImageFile.py
cisa.gov
NVD API
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-3199