AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2021-3199.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSCRITICAL / 9.8CVSS 3.1 · nvd@nist.gov
EXPLOITATION STATUSCISA known exploitedAdded Oct 08, 2026
RECORD STATUSAnalyzedModified Oct 09, 2026

Disclosure summary

Directory traversal with remote code execution can occur in /upload in ONLYOFFICE Document Server before 5.6.3, when JWT is used, via a /.. sequence in an image upload parameter.

CISA remediation guidance

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Source-reported weakness categories

CWE-22

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

NIST National Vulnerability Database · NVD-CVE-2021-3199

Open original source · Updated Oct 09, 2026

Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.

VendorProduct / associationVersion / bounds
onlyofficedocument_server* {"versionEndExcluding":"5.6.3"}

Original records & references

PUBLISHED 2021-01-26T13:16:28-05:00
MODIFIED 2026-10-09T10:20:47-04:00
INGESTED 2026-10-10T20:50:19-04:00