## Overview
CISA added CVE-2021-3199 to its Known Exploited Vulnerabilities (KEV) list on October 8, 2026. This vulnerability affects ONLYOFFICE Docs versions prior to 5.6.3. The addition to the KEV list indicates a federal deadline for remediation due to evidence of active exploitation.
## Technical Details
CVE-2021-3199 is a path traversal vulnerability that occurs when JSON Web Tokens (JWT) are used. Attackers can exploit this flaw by using a `/..` sequence in an image upload parameter. This allows unauthorized file access on the server, potentially leading to remote code execution. The vulnerability exists specifically in the `/upload` directory of ONLYOFFICE Document Server.
## Impact
Successful exploitation of this vulnerability can allow attackers to execute arbitrary code on the server. This could lead to data breaches, unauthorized access to sensitive information, or further compromise of the network. Given the high CVSS score of 9.8, the risk is significant, especially for organizations using the affected software in production environments.
## Mitigation
Defenders should immediately upgrade ONLYOFFICE Docs to version 5.6.3 or later to mitigate this vulnerability. Additionally, organizations should review their configurations to ensure that JWT is implemented securely. Regular security assessments and monitoring for unusual activity in the upload directory are also recommended to detect potential exploitation attempts.
CSURFACE Threat Sensor