logo

CVE-2026-27728 (CVSS 10): Critical Command Injection Flaw in OneUptime Probe Enables Full Server Takeover

ID: c137dbc7-8f35-5cbf-a9d8-647cb2319577

STIX ID: report--c137dbc7-8f35-5cbf-a9d8-647cb2319577

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-03-02

Date Updated: 2026-04-23

Author: Ddos

...
...

OneUptime disclosed a critical OS command injection vulnerability (CVE-2026-27728, CVSS 10.0) in its NetworkPathMonitor where unsanitized traceroute destination input allows authenticated users to execute arbitrary shell commands and achieve RCE; the maintainers have released a patch to sanitize input and mitigate the issue.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.