CVE-2026-32598

⚪ Do wiadomości

Logowanie pełnego URL z tokenem resetującym w OneUptime umożliwia przejęcie konta przez osoby z dostępem do logów aplikacji.

CVSS
6.5
EPSS
0.3%
Exploit
poc
Vendor
hackerbay
Opis źródłowy (NVD)

OneUptime is a solution for monitoring and managing online services. Prior to 10.0.24, the password reset flow logs the complete password reset URL — containing the plaintext reset token — at INFO log level, which is enabled by default in production. Anyone with access to application logs (log aggregation, Docker logs, Kubernetes pod logs) can intercept reset tokens and perform account takeover on any user. This vulnerability is fixed in 10.0.24.

exploit Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS6.5
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.3%
Opublikowano (NVD)2026-03-13 19:55:09 UTC
Ostatnia modyfikacja (NVD)2026-10-07 08:10:00 UTC
Referencje