Skip to content
CVE Alert: CVE-2021-3199 – n/a – n/a

CVE Alert: CVE-2021-3199 – n/a – n/a

Redpacketsecurity •admin • October 8, 2026

Directory traversal with remote code execution can occur in /upload in ONLYOFFICE Document Server before 5.6.3, when JWT is used, via a /.. sequence in an image upload parameter.

**Risk verdict:** Urgent: active exploitation is indicated, and the issue is automatable with potential for complete system compromise.

**Why this matters:** Successful exploitation could give an unauthorised attacker control over the document-processing service, exposing or altering data and disrupting document workflows. Public proof-of-concept code lowers the effort needed to attempt exploitation; the supplied data does not establish the prevalence or success rate of attacks.

**Most likely attack path:** An attacker can reach the service over the network without prior privileges or user interaction, targeting its upload functionality; JWT use is a relevant condition. Low attack complexity and unchanged scope suggest impact is initially confined to the vulnerable service, though access to its files, credentials or connected systems could enable follow-on activity.

**Who is most exposed:** Organisations running internet-accessible collaborative document services, especially where upload endpoints are reachable from untrusted networks and JWT is enabled.

Review upload access logs for traversal sequences, unusual image parameters and unexpected request patterns.

Check for unexpected files, processes or outbound connections originating from the service.

Correlate suspicious uploads with authentication records and subsequent access to sensitive files.

Hunt for indicators from available proof-of-concept implementations.

Mitigation and prioritisation

Upgrade to a fixed, supported release as soon as operationally feasible.

Until patched, restrict access to upload endpoints to trusted networks; assess whether JWT can be disabled safely.

Validate and normalise upload paths, and block traversal patterns at the application or reverse-proxy layer.

Preserve logs and evidence before remediation; test the upgrade and integrations in staging, then expedite production change approval.

A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.

Extracted Entities