VulnTracker[verified]@vuln_trackerDisclosure
OneUptime’s probe monitoring has a critical OS command injection vulnerability (CVE-2026-27728) that allows full system command execution via unsanitized traceroute input. No patch, exploit code, or active exploitation details are provided.
Dr.Mashari[verified]@GMashariDisclosure
CVE-2026-27728 is a critical command injection flaw in OneUptime Probe that allows full server takeover; patching is urgently recommended.
ThreatCluster[verified]@threatclusterPatch
CVE-2026-27728 is an authenticated command injection vulnerability in OneUptime Probe servers before version 10.0.7, allowing full takeover; immediate patching is advised.
ThreatSynop[verified]@ThreatSynopDisclosure
CVE-2026-27728 is a command‑injection vulnerability in OneUptime’s Probe Server that enables OS command execution; users are advised to upgrade to 10.0.7+ and audit inputs to prevent RCE.
Karma-X[verified]@Karma_X_IncDisclosure
The article announces a critical command injection vulnerability (CVE-2026-27728) in OneUptime Probe that could allow full server takeover, with a CVSS score of 10.
CVETodo[verified]@CveTodoDisclosure
The post discloses an OS command injection vulnerability in OneUptime’s NetworkPathMonitor.performTraceroute() that allows authenticated project users to execute arbitrary OS commands on the Probe server.
Gray Hats@the_yellow_fallPatch
OneUptime released version 10.0.7 to patch CVE-2026-27728, a critical command injection flaw that could allow attackers to execute root commands via traceroute probes and steal data.
iototsecnews@iototsecnewsDisclosure
The article announces the discovery of a command injection vulnerability (CVE-2026-27728) in OneUptime’s Probe server that could allow attackers to execute arbitrary OS commands and potentially take full control of the system, but it does not mention any exploit code, active attacks, or available mitigations.