Skip to content
payloadreport
Saturday, October 10, 2026Cybersecurity news without the noise70 reports
Vulnerabilities

ONLYOFFICE Docs RCE via path traversal gets CISA KEV status, federal deadline Oct 11

Federal agency mandates urgent action for critical remote code execution flaw in document server software.

ONLYOFFICE Docs RCE via path traversal gets CISA KEV status, federal deadline Oct 11
Illustration: Payload Report

Key points

  • CVE-2021-3199 allows remote code execution via path traversal in image uploads
  • CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on 8 October 2026
  • Federal systems must apply mitigations by 11 October 2026

The Cybersecurity and Infrastructure Security Agency added a critical path traversal vulnerability in ONLYOFFICE Docs to its Known Exploited Vulnerabilities catalog on 8 October 2026. The flaw, identified as CVE-2021-3199, enables attackers to execute arbitrary code remotely by exploiting directory traversal sequences within image upload parameters.

According to the National Vulnerability Database, the issue affects ONLYOFFICE Document Server versions prior to 5.6.3 when JSON Web Tokens are used for authentication. Attackers can inject a `../` sequence into the upload endpoint to traverse directories and achieve remote code execution. The NVD assigns the vulnerability a CVSS score of 9.8, rating it as critical. The weakness is classified under CWE-22, indicating improper limitation of a pathname to a restricted directory.

Regulatory context and requirements

CISA’s inclusion of CVE-2021-3199 in the KEV catalog triggers mandatory remediation requirements for federal civil executive branch systems. Under Binding Operational Directive 26-04, agencies must prioritise security updates based on risk. The federal due date for applying mitigations is 11 October 2026. Stakeholders are required to evaluate the internet exposure of each asset and ensure adherence to patching guidelines. If mitigations are unavailable, agencies must discontinue use of the affected product. The directive also references CISA’s forensics triage requirements for incident response.

Affected environments

The vulnerability exists in the ONLYOFFICE Document Server component, specifically within the `/upload` endpoint. It requires the use of JWTs for authentication to be exploitable. Any deployment running versions earlier than 5.6.3 is potentially vulnerable. The path traversal mechanism allows an attacker to bypass directory restrictions by manipulating the image upload parameter. This can lead to full remote code execution on the host system.

What happens next

Organisations must immediately verify their ONLYOFFICE Document Server versions. Those running versions before 5.6.3 should assess their exposure to the internet and check for active exploitation indicators. Federal agencies must comply with the 11 October deadline for mitigation. Non-federal entities should treat the KEV listing as a strong signal to accelerate remediation efforts.

What to do and how to stay safe: ONLYOFFICE

  • Inventory all instances of ONLYOFFICE Document Server and verify version numbers against the 5.6.3 threshold
  • Restrict network access to the `/upload` endpoint to trusted internal networks only
  • Monitor logs for unusual image upload attempts or directory traversal patterns

Step-by-step guide: Vulnerability Scanning for Small Teams: Practical Steps and Limits

General security guidance from the Payload Report newsroom. It is not confirmed advice from the organisations named in this story.

Frequently asked questions

Which versions of ONLYOFFICE Docs are affected by CVE-2021-3199?

Only versions of ONLYOFFICE Document Server prior to 5.6.3 are affected by this vulnerability.

What is the CVSS score for this path traversal flaw?

The National Vulnerability Database rates CVE-2021-3199 with a CVSS score of 9.8, which is critical.

What is the deadline for federal agencies to mitigate this issue?

Federal systems must apply mitigations by 11 October 2026, as per CISA’s KEV catalog entry.

Sources

  1. CISA KEV catalog
ONLYOFFICECVE-2021-3199CISApath traversalremote code execution

Related stories