VendorsHackerbayoneuptimeall versions
Vulnerabilities

Hackerbay OneUptime

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

23CVEs
CVE-2026-27728
OneUptime: OS Command Injection in Probe NetworkPathMonitor via unsanitized destination in traceroute exec()
Published 2026-02-25 · Analyzed
9.9EPSS 0.025
CVE-2026-33396
OneUptime has sandbox escape in Synthetic Monitor Playwright runtime allows project members to execute arbitrary commands on Probe
Published 2026-03-26 · Analyzed
9.9EPSS 0.012
CVE-2026-30957
OneUptime Synthetic Monitor RCE via exposed Playwright browser object
Published 2026-03-10 · Analyzed
9.9EPSS 0.011
CVE-2026-32306
OneUptime ClickHouse SQL Injection via Aggregate Query Parameters
Published 2026-03-12 · Analyzed
9.9EPSS 0.009
CVE-2026-27574
OneUptime: node:vm sandbox escape in probe allows any project member to achieve RCE
Published 2026-02-21 · Analyzed
9.9EPSS 0.006
CVE-2026-30887
OneUptime Affected by Unsandboxed Code Execution in Probe Allows Any Project Member to Achieve RCE
Published 2026-03-09 · Analyzed
9.9EPSS 0.006
CVE-2026-30921
OneUptime Synthetic Monitor RCE via exposed Playwright browser object
Published 2026-03-09 · Analyzed
9.9EPSS 0.005
CVE-2026-30956
OneUptime has authorization bypass via client‑controlled is-multi-tenant-query header
Published 2026-03-10 · Analyzed
9.9EPSS 0.005
CVE-2026-35053
OneUptime: Unauthenticated Workflow Execution via ManualAPI
Published 2026-04-02 · Analyzed
9.8EPSS 0.008
CVE-2026-34759
OneUptime: Unauthenticated notification API endpoints - financial abuse via phone number purchase, service disruption, and SMTP credential exposure
Published 2026-04-02 · Analyzed
9.2EPSS 0.007
CVE-2026-34758
OneUptime: Missing Authentication on Notification Endpoints
Published 2026-04-02 · Analyzed
9.1EPSS 0.005
CVE-2026-28787
OneUptime has WebAuthn 2FA bypass: server accepts client-supplied challenge instead of server-stored value, allowing credential replay
Published 2026-03-06 · Analyzed
9.0EPSS 0.004
CVE-2025-65966
OneUptime Unauthorized User Creation via API
Published 2025-11-26 · Analyzed
8.8EPSS 0.003
CVE-2026-33143
OneUptime: WhatsApp Webhook Missing Signature Verification
Published 2026-03-20 · Analyzed
8.7EPSS 0.002
CVE-2026-30958
OneUptime: Path Traversal — Arbitrary File Read (No Auth)
Published 2026-03-10 · Analyzed
8.6EPSS 0.012
CVE-2026-30920
OneUptime has broken access control in GitHub App installation flow that allows unauthorized project binding
Published 2026-03-09 · Analyzed
8.6EPSS 0.002
CVE-2024-29194
OneUptime Vulnerable to a Privilege Escalation via Local Storage Key Manipulation
Published 2024-03-24 · Analyzed
8.3EPSS 0.007
CVE-2025-66028
OneUptime is Vulnerable to Privilege Escalation via Login Response Manipulation
Published 2025-11-26 · Analyzed
8.2EPSS 0.003
CVE-2026-33142
OneUptime: ClickHouse SQL Injection via unvalidated column identifiers in sort, select, and groupBy parameters
Published 2026-03-20 · Analyzed
8.1EPSS 0.004
CVE-2026-34840
OneUptime SSO: Multi-Assertion Identity Injection via Decoupled Signature Verification
Published 2026-04-02 · Analyzed
8.1EPSS 0.003
CVE-2026-32308
OneUptime: Stored XSS via Mermaid Diagram Rendering (securityLevel: "loose")
Published 2026-03-12 · Analyzed
7.6EPSS 0.003
CVE-2026-32598
OneUptime: Password Reset Token Logged at INFO Level
Published 2026-03-12 · Analyzed
6.9EPSS 0.003
CVE-2026-30959
OneUptime has WhatsApp Resend Verification Authorization Bypass
Published 2026-03-10 · Analyzed
5.3EPSS 0.004