# ONLYOFFICE Docs (Document Server) Path Traversal Leading to Remote Code Execution (CVE-2021-3199) Exploited in the Wild

> CVE-2021-3199 is a path traversal flaw in the /upload endpoint of ONLYOFFICE Document Server before 5.6.3 (when JWT is used) that allows unauthenticated remote code execution via a /.. sequence in an image upload parameter. CISA added it to the KEV catalog on 2026-10-08 and HKCERT reports active exploitation.

- **Published:** 2026-10-09T00:00:00Z
- **Last reviewed:** 2026-10-09T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3076
- **ID:** TL-2026-3076
- **Severity:** HIGH (CVSS 9.8)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 6 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2021-3199

## Description

CVE-2021-3199 is a directory traversal vulnerability (CWE-22) in the /upload handler of ONLYOFFICE Document Server (ONLYOFFICE Docs) versions earlier than 5.6.3, reachable when JWT authentication is enabled, via a /.. sequence in an image upload parameter. NVD scores it CVSS v3.1 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) and CVSS v2.0 7.5. The vendor changelog for Document Server 5.6.3 records the fix as 'Fix Path Traversal vulnerability via image upload params (Bug #46113)'. The same changelog shows a recurring class of file-handling path-traversal fixes in preceding releases: 5.6.2 fixed traversal via the savefile parameter (Bug #46037), 5.6.1 fixed traversal via the Convert Service parameter (Bug #45976), and 5.5.3 fixed a JWT-related security problem specifically in the image-upload flow — indicating the upload/convert pipeline has been a recurring weakness area across several consecutive releases.

Publicly available proof-of-concept exploit code (poc_uploadImageFile.py, circulated via GitHub poc_exploits repositories) demonstrates the technique end-to-end for authorized testing/detection-validation purposes: it crafts a JWT-signed request to the Document Server upload endpoint containing an encoded path-traversal sequence in the image-upload parameter so that attacker-supplied file content is written outside the intended upload directory into a server-side location under the application's FileConverter/docbuilder component tree; a subsequent request to the docbuilder conversion endpoint causes the written file to be processed/executed by the server, yielding remote command execution in the context of the Document Server process. Because the flow only requires a validly-structured JWT (which in many real-world deployments is signed with a weak, default, or otherwise obtainable secret) rather than an authenticated user session, the vulnerability is effectively exploitable pre-auth from the attacker's perspective against internet-facing instances.

HKCERT's 2026-10-09 bulletin (High Risk) and the CISA KEV catalog entry added 2026-10-08 both state the flaw is being exploited in the wild, with CISA setting a remediation due date of 2026-10-11 under BOD 26-04 guidance, including an option to discontinue use of the product if vendor mitigation cannot be applied in time. ONLYOFFICE Document Server is widely deployed as a self-hosted or embedded document collaboration/editing backend (standalone installs, Nextcloud/ownCloud integrations, and other platforms that embed it), making internet-exposed instances with JWT enabled but using weak/default signing secrets, or instances still running pre-5.6.3 code, the primary at-risk population. Successful exploitation grants code execution on the document-conversion server, which routinely has access to uploaded/converted business documents and can serve as a pivot point into the hosting environment or into connected platforms (e.g., Nextcloud document-editing integrations).

## MITRE ATT&CK

- T1595.002 Active Scanning: Vulnerability Scanning
- T1588.005 Exploits
- T1585.001 Establish Accounts: Social Media Accounts
- T1190 Exploit Public-Facing Application
- T1059.006 Command and Scripting Interpreter: Python
- T1059.004 Command and Scripting Interpreter: Unix Shell
- T1505.003 Server Software Component: Web Shell
- T1574 Hijack Execution Flow
- T1071.001 Application Layer Protocol: Web Protocols
- T1571 Non-Standard Port
- T1489 Service Stop

## Sources

- [HKCERT: ONLYOFFICE Docs Remote Code Execution Vulnerability](https://www.hkcert.org/security-bulletin/onlyoffice-docs-remote-code-execution-vulnerability_20261009)
- [ONLYOFFICE DocumentServer CHANGELOG (5.6.3 fix entry)](https://github.com/ONLYOFFICE/DocumentServer/blob/903fe5ab7a275bd69c3c3346af2d21cf87ebeabf/CHANGELOG.md#563)
- [CISA Known Exploited Vulnerabilities Catalog: CVE-2021-3199](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-3199)
- [NVD - CVE-2021-3199 Detail](https://nvd.nist.gov/vuln/detail/CVE-2021-3199)
- [NVD CVE API record for CVE-2021-3199](https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2021-3199)
- [CIRCL CVE-2021-3199 vulnerability record](https://cve.circl.lu/vuln/CVE-2021-3199)
- [GitHub: CVE-2021-3199 proof-of-concept (poc_uploadImageFile.py)](https://github.com/imlonghao/poc_exploits)
- [GitHub mirror: CVE-2021-3199 PoC (moehw/poc_exploits)](https://github.com/moehw/poc_exploits/tree/master/CVE-2021-3199)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3076
