Vulnerability
Published 2026-10-08
Verified 2026-10-08

ONLYOFFICE Docs (CVE-2021-3199)

ONLYOFFICE Docs Server Path Traversal Vulnerability. ONLYOFFICE Docs contains a path traversal vulnerability that can occur when JWT is used, via a /.. sequence in an image upload parameter and could allow for remote code execution. Apply vendor mitigations. Check the NVD record and the vendor advisory for affected versions and the patch.

Product
ONLYOFFICE Docs
Exploited in Australia?
unknown

Primary: NVD · Vendor: CISA KEV · CVE: CVE-2021-3199

vulnerabilities