CVE-2026-35053
🔴 Łataj teraz
Brak uwierzytelnienia w OneUptime pozwala na zdalne uruchamianie dowolnych workflowów.
CVSS
9.8
EPSS
0.8%
Exploit
poc
Vendor
hackerbay
Opis źródłowy (NVD)
OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, the Worker service's ManualAPI exposes workflow execution endpoints (GET /workflow/manual/run/:workflowId and POST /workflow/manual/run/:workflowId) without any authentication middleware. An attacker who can obtain or guess a workflow ID can trigger arbitrary workflow execution with attacker-controlled input data, enabling JavaScript code execution, notification abuse, and data manipulation. This issue has been patched in version 10.0.42.
exploit
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 9.8 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.8% |
| Opublikowano (NVD) | 2026-04-02 20:16:29 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-06 22:10:00 UTC |
Referencje
- https://github.com/OneUptime/oneuptime/releases/tag/10.0.42 ([email protected]) [Product, Release Notes]
- https://github.com/OneUptime/oneuptime/security/advisories/GHSA-6c3w-7xg4-4cf7 ([email protected]) [Exploit, Vendor Advisory]