Home › Intelligence › Brief
VULNERABILITY BRIEF🔴 Critical Vulnerability

Critical Path Traversal (CVE‑2021‑3199) in ONLYOFFICE Docs Enables Remote Code Execution

A path traversal flaw in ONLYOFFICE Docs (CVE‑2021‑3199) allows an attacker to embed a '..' sequence in an image‑upload request, bypassing JWT checks and potentially executing arbitrary code on the server. The vulnerability affects both SaaS and on‑premises deployments, raising immediate concerns for organizations that must prove secure third‑party component management.

LiveThreat™ Intelligence · 📅 October 09, 2026· 📰 nvd.nist.gov
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
4 recommended
📰
Source
nvd.nist.gov

Critical Path Traversal (CVE‑2021‑3199) in ONLYOFFICE Docs Enables Remote Code Execution

What It Is – ONLYOFFICE Docs contains a server‑side path traversal flaw (CVE‑2021‑3199). An attacker can embed a “/..” sequence in the image‑upload parameter while a JWT token is being processed, causing the application to read or write files outside the intended directory and potentially execute arbitrary code.

Exploitability – Publicly disclosed; proof‑of‑concept code is available. The CVSS v3.1 base score is 9.8 (Critical), indicating a high likelihood of remote exploitation without authentication.

Affected Products – ONLYOFFICE Docs (on‑premises and SaaS deployments) that accept image uploads with JWT‑based authentication.

Why It Matters for Trust & Control Assurance

  • Control Mapping – The flaw tests the “secure configuration and vulnerability remediation” control objective, a single control that maps to many frameworks (e.g., NIST CSF 2.0, ISO 27001, SOC 2).
  • Continuous Monitoring – Demonstrates the need for ongoing third‑party component scanning and evidence collection to prove due diligence.
  • Audit Readiness – Remediation evidence (patch deployment, configuration hardening) becomes a defensible artifact for auditors demanding a trusted supply‑chain posture.

Recommended Actions

  • Apply the vendor‑released patch for CVE‑2021‑3199 immediately.
  • Review and tighten JWT validation logic to reject “/..” sequences.
  • Integrate ONLYOFFICE Docs into your automated vulnerability‑scanning pipeline.
  • Document the remediation steps in your control‑evidence repository for audit purposes.

Source: CISA KEV – CVE‑2021‑3199

📰 Original Source
https://nvd.nist.gov/vuln/detail/CVE-2021-3199 ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →