📦 Oneuptime

by Hackerbay

🔍 What is Oneuptime?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2026-27728

CRITICAL CVSS 9.9 Feb 25, 2026

CVE-2026-27728 is an OS command injection vulnerability in OneUptime's NetworkPathMonitor.performTraceroute() function that allows authenticated project users to execute arbitrary operating system com...

CVE-2026-27574

CRITICAL CVSS 9.9 Feb 21, 2026

CVE-2026-27574 allows remote code execution in OneUptime monitoring software. Any user with ProjectMember role (including anonymous users via open registration) can execute arbitrary code that escapes...

CVE-2025-66028

HIGH CVSS 8.2 Nov 26, 2025

OneUptime versions before 8.0.5567 contain a privilege escalation vulnerability where attackers can manipulate the login response to gain admin dashboard access. By intercepting and changing the 'isMa...

CVE-2025-65966

HIGH CVSS 8.1 Nov 26, 2025

In OneUptime version 9.0.5598, low-permission users can bypass the intended user interface and create new accounts directly through API requests. This improper authorization vulnerability affects all ...

CVE-2024-29194

HIGH CVSS 8.3 Mar 24, 2024

This CVE describes an authorization bypass vulnerability in OneUptime where attackers can manipulate client-side stored data to gain administrative privileges. By changing the is_master_admin key from...