Threat reportVulnerabilityTL-2026-3076

ONLYOFFICE Docs (Document Server) Path Traversal Leading to Remote Code Execution (CVE-2021-3199) Exploited in the Wild

highACTIVE

ONLYOFFICE Docs (Document Server) Path Traversal Leading to (TL-2026-3076), also tracked as ONLYOFFICE Docs Server Path Traversal Vulnerability, is a high-severity software vulnerability scored CVSS 9.8, first published 2026-10-09. It has no confirmed attribution, affects ONLYOFFICE Document Server (ONLYOFFICE Docs), references 1 CVE (CVE-2021-3199), maps to 11 MITRE ATT&CK techniques (T1059.004, T1059.006, T1071.001), and is covered by 9 detection rules and 6 indicators of compromise.

CVSS
9.8/10High
CVEs
1Referenced vulnerabilities
Techniques
11MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
6Indicators of compromise

Key facts for TL-2026-3076

Threat ID
TL-2026-3076
Also known as
ONLYOFFICE Docs Server Path Traversal Vulnerability
Severity
HIGH
CVSS
9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
technology, government administration, education, professional services
Target regions
Global, Asia Pacific
Detection rules
9
Indicators of compromise
6

Malware and tooling in ONLYOFFICE Docs (Document Server) Path Traversal Leading to

Malware and tooling: poc_uploadImageFile.py

How ONLYOFFICE Docs (Document Server) Path Traversal Leading to works

CVE-2021-3199 is a path traversal flaw in the /upload endpoint of ONLYOFFICE Document Server before 5.6.3 (when JWT is used) that allows unauthenticated remote code execution via a /.. sequence in an image upload parameter. CISA added it to the KEV catalog on 2026-10-08 and HKCERT reports active exploitation.

CVE-2021-3199 is a directory traversal vulnerability (CWE-22) in the /upload handler of ONLYOFFICE Document Server (ONLYOFFICE Docs) versions earlier than 5.6.3, reachable when JWT authentication is enabled, via a /.. sequence in an image upload parameter. NVD scores it CVSS v3.1 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) and CVSS v2.0 7.5. The vendor changelog for Document Server 5.6.3 records the fix as 'Fix Path Traversal vulnerability via image upload params (Bug #46113)'. The same changelog shows a recurring class of file-handling path-traversal fixes in preceding releases: 5.6.2 fixed traversal via the savefile parameter (Bug #46037), 5.6.1 fixed traversal via the Convert Service parameter (Bug #45976), and 5.5.3 fixed a JWT-related security problem specifically in the image-upload flow — indicating the upload/convert pipeline has been a recurring weakness area across several consecutive releases.

Publicly available proof-of-concept exploit code (poc_uploadImageFile.py, circulated via GitHub poc_exploits repositories) demonstrates the technique end-to-end for authorized testing/detection-validation purposes: it crafts a JWT-signed request to the Document Server upload endpoint containing an encoded path-traversal sequence in the image-upload parameter so that attacker-supplied file content is written outside the intended upload directory into a server-side location under the application's FileConverter/docbuilder component tree; a subsequent request to the docbuilder conversion endpoint causes the written file to be processed/executed by the server, yielding remote command execution in the context of the Document Server process. Because the flow only requires a validly-structured JWT (which in many real-world deployments is signed with a weak, default, or otherwise obtainable secret) rather than an authenticated user session, the vulnerability is effectively exploitable pre-auth from the attacker's perspective against internet-facing instances.

HKCERT's 2026-10-09 bulletin (High Risk) and the CISA KEV catalog entry added 2026-10-08 both state the flaw is being exploited in the wild, with CISA setting a remediation due date of 2026-10-11 under BOD 26-04 guidance, including an option to discontinue use of the product if vendor mitigation cannot be applied in time. ONLYOFFICE Document Server is widely deployed as a self-hosted or embedded document collaboration/editing backend (standalone installs, Nextcloud/ownCloud integrations, and other platforms that embed it), making internet-exposed instances with JWT enabled but using weak/default signing secrets, or instances still running pre-5.6.3 code, the primary at-risk population. Successful exploitation grants code execution on the document-conversion server, which routinely has access to uploaded/converted business documents and can serve as a pivot point into the hosting environment or into connected platforms (e.g., Nextcloud document-editing integrations).

MITRE ATT&CK techniques used in TL-2026-3076

Execution

T1059.004 Command and Scripting Interpreter: Unix Shell; T1059.006 Command and Scripting Interpreter: Python

Command and Control

T1071.001 Application Layer Protocol: Web Protocols; T1571 Non-Standard Port

Initial Access

T1190 Exploit Public-Facing Application

Impact

T1489 Service Stop

Persistence

T1505.003 Server Software Component: Web Shell

Defense Evasion

T1574 Hijack Execution Flow

Resource Development

T1585.001 Establish Accounts: Social Media Accounts; T1588.005 Exploits

Reconnaissance

T1595.002 Active Scanning: Vulnerability Scanning

Affected products and versions in ONLYOFFICE Docs (Document Server) Path Traversal Leading to

  • ONLYOFFICE — Document Server (ONLYOFFICE Docs)
    Vulnerable versions: < 5.6.3
    Fixed in: 5.6.3; later releases

Remediation for ONLYOFFICE Docs (Document Server) Path Traversal Leading to

Patches

  • ONLYOFFICE Document Server 5.6.3 (Bug #46113 fix) and later

Immediate actions

  • Upgrade ONLYOFFICE Document Server to version 5.6.3 or later immediately
  • If upgrade is not immediately possible, restrict network access to the Document Server /upload and /docbuilder endpoints to trusted hosts only
  • Rotate and strengthen the JWT secret used for Document Server authentication; verify it is not left at a default/weak value
  • Review Document Server access logs and filesystem under the FileConverter/docbuilder directory tree for unexpected or recently modified files
  • Per CISA BOD 26-04 guidance, apply vendor mitigations by the due date (2026-10-11) or discontinue exposure of the product if mitigation cannot be applied

Workarounds

  • Disable or firewall the image-upload and docbuilder endpoints from untrusted networks until patched
  • Enforce a strong, unique JWT secret and validate JWT signature/expiry strictly at the reverse proxy layer

Longer-term hardening

  • Place ONLYOFFICE Document Server behind a WAF/reverse proxy that blocks path-traversal sequences in upload parameters
  • Run Document Server with least-privilege filesystem permissions so the service account cannot write outside its designated upload/working directories
  • Deploy file-integrity monitoring on the Document Server installation directory, especially the FileConverter/bin/docbuilder path
  • Segment document-conversion infrastructure from sensitive internal networks given its exposure to untrusted user-supplied files
  • Track future ONLYOFFICE security advisories given the recurring history of upload/convert-path traversal CVEs in this component

CVEs associated with ONLYOFFICE Docs (Document Server) Path Traversal Leading to

CVE-2021-3199

Weaknesses (CWE) in ONLYOFFICE Docs (Document Server) Path Traversal Leading to

CWE-22

Timeline of ONLYOFFICE Docs (Document Server) Path Traversal Leading to

  • CVE-2021-3199 published to NVD, describing the ONLYOFFICE Document Server path traversal/RCE flaw.
  • ONLYOFFICE releases Document Server 5.6.3 containing the fix for the path traversal vulnerability via image upload params (Bug #46113).
  • Public proof-of-concept exploit code (poc_uploadImageFile.py) for CVE-2021-3199 circulated via GitHub poc_exploits repositories.
  • NVD record for CVE-2021-3199 last modified, reflecting the renewed exploitation activity and KEV listing.
  • CISA adds CVE-2021-3199 to the Known Exploited Vulnerabilities catalog, setting a remediation due date of 2026-10-11 under BOD 26-04.
  • Threadlinqs hunt pipeline ingests the HKCERT bulletin and opens TL-2026-3076 for research and detection coverage.
  • HKCERT publishes a High Risk security bulletin on the ONLYOFFICE Docs RCE vulnerability, confirming active exploitation in the wild.

Sources cited for ONLYOFFICE Docs (Document Server) Path Traversal Leading to

Detection coverage for TL-2026-3076

As of 2026-10-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3076 across Splunk SPL, Microsoft KQL and Sigma, covering 6 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
6 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats