ONLYOFFICE Docs Server Path Traversal Vulnerability
ONLYOFFICE · Docs
Date added (CISA)
2026-10-08
Remediation due
2026-10-11
Known ransomware use
Not indicated
Remediation priority
P2 — CISA due date imminent
Description
ONLYOFFICE Docs contains a path traversal vulnerability that can occur when JWT is used, via a /.. sequence in an image upload parameter and could allow for remote code execution.