logo

Maximum 10.0 CVSS Flaws in OneUptime Allow Full Account Takeovers and RCE

ID: 5d39c623-5868-5b30-a0b2-0ac7e9c4cfe9

STIX ID: report--5d39c623-5868-5b30-a0b2-0ac7e9c4cfe9

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-03-11

Date Updated: 2026-04-23

Author: Ddos

...
...

OneUptime released urgent patches for two maximum-severity CVEs (CVE-2026-30956 and CVE-2026-30957) that allow a low-privileged user to bypass tenant isolation and access or exfiltrate other tenants' data (including password reset tokens), and to perform server-side remote code execution via an exposed Playwright object in the Synthetic Monitor; self-hosted instances running 10.0.20 or lower must be updated immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.