OneUptime Command Injection Vulnerability Poses Major Risk of Full System Takeover
ID: 0c77adea-167c-5a4d-a3c5-527d3422dc18
STIX ID: report--0c77adea-167c-5a4d-a3c5-527d3422dc18
Feed Name: GBHackers
Threat Score
A critical command-injection vulnerability (CVE-2026-27728) in OneUptime’s Probe Server allows authenticated project users to inject shell metacharacters into the traceroute destination field, leading to remote code execution and potential full system compromise; OneUptime patched the issue in version 10.0.7 by replacing exec() with execFile(), and the report urges immediate patching, configuration audits, monitoring, and interim isolation/workarounds.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
