CVE-2026-27574Disclosure(hackerbay / oneuptime)

LOWCVSS 9.9 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch hackerbay oneuptime systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

OneUptime is a solution for monitoring and managing online services. In versions 9.5.13 and below, custom JavaScript monitor feature uses Node.js's node:vm module (explicitly documented as not a security mechanism) to execute user-supplied code, allowing trivial sandbox escape via a well-known one-liner that grants full access to the underlying process. Because the probe runs with host networking and holds all cluster credentials (ONEUPTIME_SECRET, DATABASE_PASSWORD, REDIS_PASSWORD, CLICKHOUSE_PASSWORD) in its environment variables, and monitor creation is available to the lowest role (ProjectMember) with open registration enabled by default, any anonymous user can achieve full cluster compromise in about 30 seconds. This issue has been fixed in version 10.0.5.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • oneuptime

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • Peaked 4d ago at 1 mentions (2026-02-22); latest day: 1
  • 5 total mentions across 5 days

Affected systems

Vendors
Products
oneuptime

Deep dive

Activity timeline5 mentions / 5d
00111Mentions · 2026-02-22: 1Mentions · 2026-02-24: 1Mentions · 2026-03-02: 1Mentions · 2026-03-07: 1Mentions · 2026-03-09: 1PoC Mentioned / Linked · 2026-03-02: 1Patch / Workaround · 2026-02-22: 1Patch / Workaround · 2026-03-02: 1Technical Details · 2026-02-22: 1Technical Details · 2026-02-24: 1Technical Details · 2026-03-02: 1Technical Details · 2026-03-07: 1Technical Details · 2026-03-09: 102-2202-2403-0203-0703-09
Signal classification2 categories
Disclosure
360.0%
Patch
240.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-221
Patch1
2026-02-241
Disclosure1
2026-03-021
Patch1
2026-03-071
Disclosure1
2026-03-091
Disclosure1
Full discourse5 posts
  • CCB Alert@CCBalert
    Patch

    Warning: Critical Sandbox Escape in #OneUptime. CVE-2026-27574 CVSS: 9.9. This flaw grants full cluster compromise. A Proof of Concept (#POC) is currently available! Update to the latest version immediately! #Patch #Patch #Patch

    Post summary

    Critical sandbox escape vulnerability (CVE-2026-27574) in OneUptime with CVSS 9.9, PoC available, and users urged to update to the latest version immediately.

    01000340
    7.2K followersView on X
  • TRONCAL Yannick@ytroncal
    Disclosure

    Remote Code Execution in OneUptime Probe via VM Sandbox Escape CVE-2026-27574: Remote Code Execution in OneUptime Probe via VM Sandbox Escape https://dev.to/cverports/ghsa-h343-gg57-2q67-cve-2026-27574-remote-code-execution-in-oneuptime-probe-via-vm-sandbox-escape-39em

    Post summary

    The post announces CVE‑2026‑27574, a remote code execution flaw in OneUptime Probe caused by a VM sandbox escape, but it provides no proof of concept, exploit code, or evidence of active exploitation.

    0000039
    132 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 OneUptime, Remote Code Execution, #CVE-2026-27574 (Critical) https://dailycve.com/oneuptime-remote-code-execution-cve-2026-27574-critical/

    Post summary

    The tweet announces the discovery of CVE‑2026‑27574, a critical remote code execution flaw in OneUptime, without providing evidence of exploits, patches, or active attacks.

    0000046
    166 followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-27574: OneUptime, One Shell: Escaping the node:vm Sandbox OneUptime, a popular open-source observability platform, suffered from a catastrophic Remote Code Execution (RCE) vulnerability due to a classic misunderstanding of Node.js internals. ... https://cvereports.com/reports/CVE-2026-27574

    Post summary

    The post announces a catastrophic RCE vulnerability in OneUptime caused by a Node.js internals misunderstanding, but it does not provide a PoC, exploit code, patch, or evidence of active exploitation.

    0000060
    31 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    A #sandboxescape flaw (CVE-2026-27574) in #OneUptime allows project members to achieve RCE via malicious probes. Remediation is available. https://www.pulsepatch.io/posts/cve-2026-27574-oneuptime-sandbox-escape-rce

    Post summary

    A sandbox escape vulnerability (CVE-2026-27574) in OneUptime allows RCE via malicious probes, but remediation is available.

    0000047
    1 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphackerbayoneuptime---

Explore more