Skip to content
Urgent CVE-2021-3199 Vulnerability in ONLYOFFICE Exploited in the Wild

Urgent CVE-2021-3199 Vulnerability in ONLYOFFICE Exploited in the Wild

First seen 9 Oct 2026, 03:31 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 9, 2026 at 04:33 UTC

A vulnerability, CVE-2021-3199, has been identified in ONLYOFFICE Document Server versions prior to 5.6.3, allowing remote code execution through a path traversal flaw when using JWT. Exploitation is confirmed in the wild, with attackers able to manipulate image upload parameters to gain unauthorized control over the document-processing service. This vulnerability poses a high risk as it can lead to complete system compromise, affecting organizations with internet-accessible collaborative document services. The issue was added to the CISA KEV catalog on 2026-10-08, indicating active exploitation. Users are advised to upgrade to version 5.6.3 or later immediately. Until then, restricting access to upload endpoints and validating upload paths is recommended.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2021-01-22
CVE-2021-3199 published
CVE-2021-3199 was published, detailing a critical path traversal vulnerability in ONLYOFFICE.
Redpacketsecurity
2026-10-08
CISA adds CVE-2021-3199 to KEV
CISA confirmed active exploitation of CVE-2021-3199 and added it to the KEV catalog.
Redpacketsecurity
2026-10-09
ONLYOFFICE vulnerability reported
HKCERT reported the remote code execution vulnerability in ONLYOFFICE Docs, confirming active exploitation.
Hkcert

More articles in this cluster (3)

Following this threat?

Track CVE-2021-3199 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which versions are affected?
ONLYOFFICE Document Server versions prior to 5.6.3 are affected by CVE-2021-3199.
Is this vulnerability being actively exploited?
Yes, exploitation of CVE-2021-3199 has been confirmed in the wild.
What immediate actions should be taken?
Upgrade to ONLYOFFICE Document Server version 5.6.3 or later as soon as possible.