- EPSS 0.02%
- Veröffentlicht 10.03.2026 17:06:33
- Zuletzt bearbeitet 12.03.2026 14:01:15
OneUptime is a solution for monitoring and managing online services. The resend-verification-code endpoint allows any authenticated user to trigger a verification code resend for any UserWhatsApp record by ID. Ownership is not validated (unlike the v...
CVE-2026-30958
- EPSS 0.16%
- Veröffentlicht 10.03.2026 17:01:43
- Zuletzt bearbeitet 12.03.2026 14:09:46
OneUptime is a solution for monitoring and managing online services. Prior to 10.0.21, an unauthenticated path traversal in the /workflow/docs/:componentName endpoint allows reading arbitrary files from the server filesystem. The componentName route ...
CVE-2026-30957
- EPSS 0.27%
- Veröffentlicht 10.03.2026 16:58:28
- Zuletzt bearbeitet 12.03.2026 14:11:29
OneUptime is a solution for monitoring and managing online services. Prior to 10.0.21, OneUptime Synthetic Monitors allow a low-privileged authenticated project user to execute arbitrary commands on the oneuptime-probe server/container. The root caus...
CVE-2026-30956
- EPSS 0.05%
- Veröffentlicht 10.03.2026 16:56:29
- Zuletzt bearbeitet 12.03.2026 14:11:58
OneUptime is a solution for monitoring and managing online services. Prior to 10.0.21, a low‑privileged user can bypass authorization and tenant isolation in OneUptime v10.0.20 and earlier by sending a forged is-multi-tenant-query header together wit...
CVE-2026-30921
- EPSS 0.02%
- Veröffentlicht 09.03.2026 22:58:58
- Zuletzt bearbeitet 12.03.2026 13:44:49
OneUptime is a solution for monitoring and managing online services. Prior to 10.0.20, OneUptime Synthetic Monitors allow low-privileged project users to submit custom Playwright code that is executed on the oneuptime-probe service. In the current im...
CVE-2026-30920
- EPSS 0.01%
- Veröffentlicht 09.03.2026 22:57:05
- Zuletzt bearbeitet 12.03.2026 13:43:38
OneUptime is a solution for monitoring and managing online services. Prior to 10.0.19, OneUptime's GitHub App callback trusts attacker-controlled state and installation_id values and updates Project.gitHubAppInstallationId with isRoot: true without v...
CVE-2026-30887
- EPSS 0.06%
- Veröffentlicht 09.03.2026 22:40:04
- Zuletzt bearbeitet 12.03.2026 13:41:22
OneUptime is a solution for monitoring and managing online services. Prior to 10.0.18, OneUptime allows project members to run custom Playwright/JavaScript code via Synthetic Monitors to test websites. However, the system executes this untrusted user...
- EPSS 0.05%
- Veröffentlicht 06.03.2026 04:55:40
- Zuletzt bearbeitet 10.03.2026 19:51:16
OneUptime is a solution for monitoring and managing online services. In version 10.0.11 and prior, the WebAuthn authentication implementation does not store the challenge on the server side. Instead, the challenge is returned to the client and accept...
CVE-2026-27728
- EPSS 0.34%
- Veröffentlicht 25.02.2026 16:25:09
- Zuletzt bearbeitet 02.03.2026 18:56:30
OneUptime is a solution for monitoring and managing online services. Prior to version 10.0.7, an OS command injection vulnerability in `NetworkPathMonitor.performTraceroute()` allows any authenticated project user to execute arbitrary operating syste...
CVE-2026-27574
- EPSS 0.02%
- Veröffentlicht 21.02.2026 10:13:03
- Zuletzt bearbeitet 23.02.2026 20:36:09
OneUptime is a solution for monitoring and managing online services. In versions 9.5.13 and below, custom JavaScript monitor feature uses Node.js's node:vm module (explicitly documented as not a security mechanism) to execute user-supplied code, allo...