Maximum 10.0 CVSS Flaws in OneUptime Allow Full Account Takeovers and RCE
ID: 5d39c623-5868-5b30-a0b2-0ac7e9c4cfe9
STIX ID: report--5d39c623-5868-5b30-a0b2-0ac7e9c4cfe9
Feed Name: securityonline.info
Threat Score
OneUptime released urgent patches for two maximum-severity CVEs (CVE-2026-30956 and CVE-2026-30957) that allow a low-privileged user to bypass tenant isolation and access or exfiltrate other tenants' data (including password reset tokens), and to perform server-side remote code execution via an exposed Playwright object in the Synthetic Monitor; self-hosted instances running 10.0.20 or lower must be updated immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
