Skip to content
ONLYOFFICE Docs Remote Code Execution Vulnerability

ONLYOFFICE Docs Remote Code Execution Vulnerability

Hkcert • October 9, 2026

A vulnerability was identified in ONLYOFFICE Docs. A remote attacker could exploit this vulnerability to trigger remote code execution and security restriction bypass on the targeted system.

CVE-2021-3199 is being exploited in the wild. ONLYOFFICE Docs contains a path traversal vulnerability that can occur when JWT is used, via a /.. sequence in an image upload parameter and could allow for remote code execution. Hence, the risk level is rated as High Risk.

Security Restriction Bypass

Remote Code Execution

System / Technologies affected

ONLYOFFICE Document Server versions earlier than 5.6.3

ONLYOFFICE Document Server to version 5.6.3 or later

Vulnerability Identifier

​​​​​​

Extracted Entities