Disclosure summary
Directory traversal with remote code execution can occur in /upload in ONLYOFFICE Document Server before 5.6.3, when JWT is used, via a /.. sequence in an image upload parameter.
CISA remediation guidance
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Source-reported weakness categories
CWE-22
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
NIST National Vulnerability Database · NVD-CVE-2021-3199
Open original source · Updated Oct 09, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
| Vendor | Product / association | Version / bounds |
|---|---|---|
| onlyoffice | document_server | * {"versionEndExcluding":"5.6.3"} |
Original records & references
- NIST NVD record
- CVE Program record
- CISA KEV catalog entry
- github.com — Release Notes, Third Party Advisory
- github.com — Exploit, Third Party Advisory
- github.com — Exploit, Third Party Advisory
- github.com — Release Notes, Third Party Advisory
- github.com — Exploit, Third Party Advisory
- github.com — Exploit, Third Party Advisory
- www.cisa.gov — US Government Resource
PUBLISHED 2021-01-26T13:16:28-05:00
MODIFIED 2026-10-09T10:20:47-04:00
INGESTED 2026-10-10T20:50:19-04:00