BREACH WATCH BRIEF Critical ☁️ Vulnerability

Critical Path Traversal (CVE‑2021‑3199) in ONLYOFFICE Docs Enables Remote Code Execution

A path traversal flaw in ONLYOFFICE Docs (CVE‑2021‑3199) allows an attacker to embed a '..' sequence in an image‑upload request, bypassing JWT checks and potentially executing arbitrary code on the server. The vulnerability affects both SaaS and on‑premises deployments, raising immediate concerns for organizations that must prove secure third‑party component management.

SeverityCritical
Type☁️ Vulnerability
ConfidenceHigh
ReportedOct 8, 2026
Technology & SaaS TECH_SAAS Vulnerability Exploit

What happened

ONLYOFFICE Docs processes image uploads that include a JWT token. When the uploaded filename contains a '/..' sequence, the application fails to sanitize the path, allowing directory traversal and remote code execution. Public proof‑of‑concept code demonstrates the exploit, and the CVSS base score is 9.8 (Critical).

Why it matters for trust and compliance

  • The issue tests the control objective of secure configuration and timely vulnerability remediation, a single control that maps to many frameworks and provides a clear audit trail for trust‑focused assessments.
  • Highlights the need for continuous third‑party vulnerability monitoring to maintain a defensible audit trail.
  • Provides evidence of patch‑management and configuration hardening that satisfies multiple framework requirements.

Who is affected

TECH_SAAS

Recommended actions

  1. Deploy the vendor’s patch for CVE‑2021‑3199 without delay.
  2. Validate and harden JWT validation to reject any '..' path sequences.
  3. Add ONLYOFFICE Docs to automated vulnerability‑scanning and continuous monitoring tools.
  4. Record remediation steps in your control‑evidence repository for audit readiness.

Details

Organizations
ONLYOFFICE
CVEs
CVE-2021-3199

Get the Breach Digest

The incidents that matter for your vendors and your data, analysed for practitioners, in one email.