Back to Intelligence

ONLYOFFICE Docs Path Traversal Now Actively Exploited — CISA KEV Detection and Remediation Guide

SA
Security Arsenal Team
October 9, 2026
9 min read

On October 8, 2026, CISA added CVE-2021-3199 — a path traversal vulnerability in ONLYOFFICE Docs — to its Known Exploited Vulnerabilities (KEV) catalog. That listing is not an academic exercise. A KEV addition means CISA has credible evidence of active exploitation in the wild right now, and it triggers mandatory remediation timelines for federal agencies under Binding Operational Directive 26-04, Prioritizing Security Updates Based on Risk. For private-sector organizations running ONLYOFFICE Docs to provide collaborative document editing, the calculus is the same: an internet-reachable, unauthenticated remote code execution path is being abused, and the window between KEV listing and broader attacker adoption is measured in days, not months.

I've led enough IR engagements against exploited collaboration and document platforms to say this plainly: these servers sit in a dangerous position. They process untrusted user content, often run with substantial filesystem access, and are frequently internet-exposed to enable external collaboration. If your ONLYOFFICE Docs instance is reachable from the internet and unpatched, treat this as a probable-compromise scenario, not a hypothetical one.

Technical Analysis

The Vulnerability

CVE-2021-3199 is a path traversal vulnerability in ONLYOFFICE Docs (DocumentServer) that manifests when JWT-based request handling is in use. The flaw is triggered via a /.. sequence in an image upload parameter, allowing an attacker to escape the intended upload directory and write attacker-controlled content to arbitrary filesystem locations. Because the vulnerable endpoint does not require valid authentication under affected configurations, exploitation chains to unauthenticated remote code execution. NVD assesses this at CVSS 3.1: 9.8 (Critical) — network vector, no privileges required, no user interaction.

The affected component is the ONLYOFFICE Docs server stack — a Node.js-based document editing/conversion service (commonly deployed as the onlyoffice-documentserver package on Debian/Ubuntu, via Docker, or integrated behind Nextcloud, ownCloud, Seafile, or custom portals). The exploitation requirements from a defender's perspective:

  • The DocumentServer must be network-reachable by the attacker (frequently TCP 80/443, often a dedicated vhost such as docs.company.com).
  • The vulnerable image upload functionality must be exposed — in JWT-enabled deployments, the traversal lives in how the upload parameter is parsed, so enabling JWT is not a mitigation against the traversal itself on vulnerable versions.
  • No credentials are required.

Why the Traversal Leads to Code Execution

Path traversal in an upload handler is a write primitive. An attacker controlling the destination path can drop a payload into web-accessible directories, overwrite application configuration, or plant files processed by the document conversion engine. Combined with the service's file-processing behavior, that write primitive becomes code execution in the context of the DocumentServer service account (ds on standard Linux packages). From there, post-exploitation follows the standard web-shell playbook: establish persistence, enumerate internal network access (these servers often sit deep in trusted segments behind the portal that embeds them), and stage data exfiltration.

Exploitation Status

  • CISA KEV: listed 2026-10-08 — confirmed active exploitation.
  • CISA's required action: apply mitigations per vendor instructions, comply with BOD 26-04 prioritization guidance and CISA's Forensics Triage Requirements, follow BOD 26-04 cloud guidance where applicable, or discontinue use of the product if mitigations are unavailable.
  • Asset owners are explicitly responsible for evaluating each affected asset — meaning federated, shadow, and dev instances count.

The 2021 vintage of this CVE is the trap. Many organizations patched or deployed DocumentServer years ago and assumed the issue was closed; CISA's listing indicates attackers are actively scanning for and exploiting instances that remain vulnerable — including forgotten integrations, test servers, and appliances bundled with third-party platforms. Attackers don't care that the CVE is old. Your exposure inventory shouldn't either.

Detection & Response

Detection priority one is the exploitation attempt itself: requests to DocumentServer upload endpoints containing /.. traversal sequences. Priority two is post-exploitation behavior: the Node.js DocumentServer processes spawning shells or writing unexpected files. The rules below are tuned against those two observable behaviors.

YAML
---
title: ONLYOFFICE Docs Path Traversal Attempt via Image Upload Endpoint
id: 3f8a2c41-7d1e-4b9a-a6c2-9e5d1f0b8a47
status: experimental
description: Detects HTTP requests to ONLYOFFICE DocumentServer endpoints containing /.. path traversal sequences in upload-related parameters, consistent with CVE-2021-3199 exploitation confirmed by CISA KEV (2026-10-08).
references:
  - https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2021-3199
  - https://attack.mitre.org/techniques/T1190/
author: Security Arsenal
date: 2026/10/09
tags:
  - attack.initial_access
  - attack.t1190
logsource:
  category: webserver
detection:
  selection_uri:
    cs-uri|contains:
      - '/..'
      - '%2f..'
      - '..%2f'
      - '%2e%2e'
  selection_upload:
    cs-uri|contains:
      - 'upload'
      - 'image'
      - 'converter'
  condition: selection_uri and selection_upload
falsepositives:
  - Rare; traversal sequences in upload parameters on document server endpoints have virtually no legitimate use
level: critical
---
title: ONLYOFFICE DocumentServer Process Spawning Shell or Script Interpreter
id: 8b1d4e92-5c3a-4f78-b2d6-1a9e0c7d5f31
status: experimental
description: Detects ONLYOFFICE Docs (DocumentServer) Node.js or converter processes spawning command shells or script interpreters, indicating post-exploitation activity following unauthenticated RCE such as CVE-2021-3199.
references:
  - https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2021-3199
  - https://attack.mitre.org/techniques/T1059/
author: Security Arsenal
date: 2026/10/09
tags:
  - attack.execution
  - attack.t1059
logsource:
  category: process_creation
  product: linux
detection:
  selection_parent:
    ParentImage|contains:
      - 'docservice'
      - 'converter'
      - '/var/www/onlyoffice'
    ParentCommandLine|contains:
      - 'DocService'
      - 'FileConverter'
  selection_child:
    Image|endswith:
      - '/bash'
      - '/sh'
      - '/dash'
      - '/python'
      - '/python3'
      - '/perl'
      - '/curl'
      - '/wget'
      - '/nc'
      - '/ncat'
  condition: selection_parent and selection_child
falsepositives:
  - DocumentServer updates and font regeneration may invoke shell scripts — validate against maintenance windows and package manager activity
level: high
KQL — Microsoft Sentinel / Defender
// Hunt for ONLYOFFICE Docs traversal attempts and suspicious request patterns in Sentinel
// Covers Syslog/CEF-ingested web/proxy logs and Defender network telemetry
let OnlyofficeHosts = (DeviceNetworkEvents
| where RemoteUrl has_any ("onlyoffice", "documentserver", "docsserver")
| summarize by RemoteUrl);
union
  (CommonSecurityLog
  | where RequestURL contains "/.." or RequestURL contains "%2e%2e" or RequestURL contains "..%2f"
  | where RequestURL has_any ("upload", "image", "converter", "onlyoffice")
  | project TimeGenerated, SourceIP, DestinationHostName, RequestURL, RequestMethod, ApplicationProtocol, DeviceAction),
  (Syslog
  | where SyslogMessage has_all ("/..", "onlyoffice")
     or SyslogMessage has_all ("..%2f", "upload")
  | project TimeGenerated, Computer, HostIP, ProcessName, SyslogMessage),
  (DeviceProcessEvents
  | where InitiatingProcessFolderPath has_any ("onlyoffice", "docservice", "converter")
  | where FileName in~ ("bash", "sh", "dash", "curl", "wget", "nc", "python3", "perl")
  | project TimeGenerated, DeviceName, InitiatingProcessCommandLine, FileName, ProcessCommandLine, AccountName)
| sort by TimeGenerated desc
VQL — Velociraptor
-- Hunt for post-exploitation artifacts on ONLYOFFICE Docs servers
-- Looks for shells/tools spawned by the ds service account and recently
-- written executable/script files under DocumentServer directories
SELECT Pid, Name, CommandLine, Exe, Username, CreateTime
FROM pslist()
WHERE (Username =~ 'ds|www-data|nginx'
   AND Name =~ '(?i)(bash|sh|dash|curl|wget|nc|ncat|python|perl)')
   OR CommandLine =~ '(?i)(/dev/tcp|base64 -d|chmod \+x|/tmp/.*\.sh)'

SELECT FullPath, Size, Mtime, Ctime, Mode
FROM glob(globs=[
  '/var/www/onlyoffice/documentserver/**/*.sh',
  '/var/www/onlyoffice/documentserver/server/**/*.jsp',
  '/tmp/**'
])
WHERE Mtime > now() - 604800
  AND Mode =~ 'x'
Bash / Shell
#!/bin/bash
# ONLYOFFICE Docs (CVE-2021-3199) exposure verification and remediation helper
# Run on the DocumentServer host (Debian/Ubuntu package deployments)

set -euo pipefail

echo "=== [1] Identify installed DocumentServer version ==="
if command -v dpkg >/dev/null 2>&1; then
  dpkg -l | grep -i onlyoffice || echo "No onlyoffice package found"
fi

echo "=== [2] Check for Docker-based DocumentServer ==="
if command -v docker >/dev/null 2>&1; then
  docker ps --format '{{.Image}} {{.Names}}' | grep -i onlyoffice || echo "No onlyoffice containers running"
fi

echo "=== [3] Hunt access logs for traversal attempts (CVE-2021-3199) ==="
LOGDIRS=(/var/log/nginx /var/log/apache2 /var/log/onlyoffice)
for d in "${LOGDIRS[@]}"; do
  [ -d "$d" ] || continue
  echo "-- Scanning $d --"
  zgrep -hE '(/\.\.|%2e%2e|\.\.%2f).*(upload|image|converter)' "$d"/*access*log* 2>/dev/null \
    | awk '{print $1, $7}' | sort | uniq -c | sort -rn | head -20 \
    || echo "No matches in $d"
done

echo "=== [4] Check for suspicious child processes of DocumentServer ==="
ps aux | grep -iE 'docservice|converter' | grep -v grep || true
pstree -p $(pgrep -f docservice | head -1) 2>/dev/null || echo "docservice not running"

echo "=== [5] Upgrade DocumentServer to latest vendor release ==="
# Vendor instructions: https://helpcenter.onlyoffice.com/installation/docs-community-index.aspx
# Backup first, then:
# sudo apt-get update && sudo apt-get install --only-upgrade onlyoffice-documentserver
# Docker: pull the latest onlyoffice/documentserver image and redeploy.

echo "=== [6] Restrict exposure (defense-in-depth while patching) ==="
# Example: limit DocumentServer to your portal/proxy IP only
# sudo ufw allow from <PORTAL_IP> to any port 443 proto tcp comment 'ONLYOFFICE restrict'
echo "Review reverse proxy ACLs; DocumentServer should not be directly internet-exposed."

Remediation

  1. Inventory every instance — including the forgotten ones. Enumerate DocumentServer deployments across VMs, Docker hosts, and bundled integrations (Nextcloud/ownCloud/Seafile appliances frequently ship or reference DocumentServer). CISA's directive makes asset owners responsible for evaluating each asset; shadow instances are exactly what KEV-driven attackers are scanning for.
  2. Upgrade immediately to the latest ONLYOFFICE Docs release following the vendor installation/upgrade documentation at https://helpcenter.onlyoffice.com/installation/docs-community-index.aspx. For Debian/Ubuntu: apt-get install --only-upgrade onlyoffice-documentserver. For Docker: pull the current onlyoffice/documentserver image and redeploy. Verify the running version post-upgrade — package installs can leave old services running behind a reverse proxy.
  3. Apply CISA's mandated actions. Follow BOD 26-04 prioritization timelines, comply with CISA's Forensics Triage Requirements (preserve logs and memory/disk evidence from exposed instances before wiping), and if you cannot patch — for example, an unsupported embedded appliance — discontinue use of the product as the directive states. There is no compensating-control carve-out that makes an unauthenticated RCE acceptable.
  4. Assume breach on exposed instances. Any DocumentServer reachable from the internet on a vulnerable version should be treated as compromised: review access logs for traversal sequences (Section [3] of the script above), hunt for service-account shell spawns, rotate any credentials or JWT secrets stored on the host, and check outbound connections from the server.
  5. Reduce the attack surface permanently. DocumentServer should sit behind your portal or reverse proxy with strict ACLs — never directly internet-exposed. Enforce TLS, restrict source networks where collaboration partners are known, and ensure JWT secrets are strong and rotated after any suspected exposure.
  6. Close the loop in vulnerability management. Add CVE-2021-3199 to your scanner's verified-findings list (not just its signature database), confirm remediation with an authenticated rescan, and feed KEV additions into your SLA engine — KEV-listed items should bypass standard patch cycles regardless of CVE age.

Related Resources

Security Arsenal Penetration Testing Services AlertMonitor Platform Book a SOC Assessment vulnerability-management Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.