logo

OneUptime Command Injection Vulnerability Poses Major Risk of Full System Takeover

ID: 0c77adea-167c-5a4d-a3c5-527d3422dc18

STIX ID: report--0c77adea-167c-5a4d-a3c5-527d3422dc18

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-03-02

Date Updated: 2026-04-22

Author: Divya

...
...

A critical command-injection vulnerability (CVE-2026-27728) in OneUptime’s Probe Server allows authenticated project users to inject shell metacharacters into the traceroute destination field, leading to remote code execution and potential full system compromise; OneUptime patched the issue in version 10.0.7 by replacing exec() with execFile(), and the report urges immediate patching, configuration audits, monitoring, and interim isolation/workarounds.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.