CVE-2026-27728Disclosure(hackerbay / oneuptime)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch hackerbay oneuptime systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OneUptime is a solution for monitoring and managing online services. Prior to version 10.0.7, an OS command injection vulnerability in `NetworkPathMonitor.performTraceroute()` allows any authenticated project user to execute arbitrary operating system commands on the Probe server by injecting shell metacharacters into a monitor's destination field. Version 10.0.7 fixes the vulnerability.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • oneuptime

Threat summary

  • Patch or workaround signal is available
  • 12 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 12 signals
  • Disclosure: 9 classified signals
  • Peaked 1d ago at 6 mentions (2026-03-02); latest day: 1
  • 12 total mentions across 4 days

Affected systems

Vendors
Products
oneuptime

Deep dive

Activity timeline12 mentions / 4d
02356Mentions · 2026-02-25: 2Mentions · 2026-02-26: 3Mentions · 2026-03-02: 6Mentions · 2026-03-09: 1Patch / Workaround · 2026-02-26: 1Patch / Workaround · 2026-03-02: 4Technical Details · 2026-02-25: 2Technical Details · 2026-02-26: 3Technical Details · 2026-03-02: 6Technical Details · 2026-03-09: 102-2502-2603-0203-09
Signal classification2 categories
Disclosure
975.0%
Patch
325.0%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-02-252
Disclosure2
2026-02-263
Disclosure2Patch1
2026-03-026
Disclosure4Patch2
2026-03-091
Disclosure1
Full discourse12 posts
  • VulnTracker@vuln_tracker
    Disclosure

    ⚠️ CVE-2026-27728 — CVSS 9.9 CRITICAL OS Command Injection in OneUptime's probe monitoring. Unsanitized input in traceroute exec() = full system command execution. If you're using OneUptime for infrastructure monitoring, your monitoring tool might be your biggest vulnerability. For details, please check out: http://vulntracker.io/cves/CVE-2026-27728 #VulnerabilityManagement #VulnerabilityIntelligence #Cybersecurity #CVE #OSCommand

    Post summary

    OneUptime’s probe monitoring has a critical OS command injection vulnerability (CVE-2026-27728) that allows full system command execution via unsanitized traceroute input. No patch, exploit code, or active exploitation details are provided.

    10030207
    361 followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    OneUptime 10.0.7 patches a critical 10.0 CVSS vulnerability (CVE-2026-27728). Attackers can use traceroute probes to execute root commands and steal data. #OneUptime #CyberSecurity #RCE #CommandInjection #InfoSec #Vulnerability #CloudSecurity #SaaS #CVE https://securityonline.info/cve-2026-27728-cvss-10-critical-command-injection-flaw-in-oneuptime-probe-enables-full-server-takeover/

    Post summary

    OneUptime released version 10.0.7 to patch CVE-2026-27728, a critical command injection flaw that could allow attackers to execute root commands via traceroute probes and steal data.

    01011362
    10.5K followersView on X
  • Dr.Mashari@GMashari
    Disclosure

    📌 ثغرة CVE-2026-27728 (CVSS 10): خلل حرج في حقن الأوامر في OneUptime Probe يتيح الاستيلاء الكامل على الخادم [leave one empty line] 🛡️ الفئة: ثغرة [leave one empty line] 📝 الملخص: تكتسي هذه الثغرة الأمنية المصنفة كـ CVE-2026-27728 أهمية قصوى نظراً لخطورتها البالغة التي بلغت 10 درجات على مقياس CVSS، حيث تستهدف مكون OneUptime Probe المسؤول عن مراقبة توفر المواقع والواجهات البرمجية. يتيح الخلل الفني للمهاجمين تنفيذ هجمات "حقن الأوامر" (Command Injection)، مما يؤدي فعلياً إلى السيطرة الكاملة على الخادم المستضيف للأداة. يهدد هذا الاختراق البنية التحتية الرقمية للمنظمات التي تعتمد على هذه المنصة لمراقبة لوحات المعلومات والخدمات الحيوية. — يُنصح بالتحقق الفوري من الإصدارات المستخدمة وتطبيق التحديثات الأمنية العاجلة لسد هذه الثغرة والثغرات المرتبطة بها مثل CVE-2026-2441. [leave one empty line] 📍 تفاصيل فنية: 🎯 الهدف: خوادم مراقبة OneUptime Probe والمنظمات التي تستخدمها لمتابعة توفر الخدمات. 🧠 التقنية المستخدمة: استغلال خلل في معالجة المدخلات لتنفيذ أوامر برمجية غير مصرح بها (Command Injection). 🛑 التوصيات الأمنية: إجراء تحديث فوري للنظام إلى النسخة المصححة وتقييد الوصول إلى واجهات المراقبة. [leave one empty line] 🗓️ تاريخ النشر: 02/03/2026 [leave one empty line] 🔗 للمزيد: https://securityonline.info/cve-2026-27728-cvss-10-critical-command-injection-flaw-in-oneuptime-probe-enables-full-server-takeover/

    Post summary

    CVE-2026-27728 is a critical command injection flaw in OneUptime Probe that allows full server takeover; patching is urgently recommended.

    01010117
    9.2K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    OneUptime プラットフォームの脆弱性 CVE-2026-27728 が FIX:システムの完全乗っ取りの恐れ https://iototsecnews.jp/2026/03/02/oneuptime-command-injection-vulnerability-poses-major-risk-of-full-system-takeover/ 監視プラットフォーム OneUptime の Probe サーバにおいて、任意の OS コマンドを実行される、深刻な脆弱性 CVE-2026-27728 が発見されました。この問題の原因は、ネットワークの経路調査を行う関数の内部で、ユーザーが入力したディスティネーション情報が、そのままシェル (コマンド実行環境) に渡され、実行されることにあります。 この脆弱な箇所では、Node.js の exec() 関数が使われており、本来は接続先のドメイン名だけが入る場所に、”;, |, &, $()” といった特殊記号の入力を許してしまいます。それにより、本来の処理を抜け出し、ファイルの読み取りやウイルス実行などの命令をサーバに実行させることが可能となってしまいます。たとえ低権限の一般ユーザーであっても、この不備を突くことで、Probe サーバの制御を完全に乗っ取ることが可能になります。ご利用のチームは、ご注意ください。 #CVE202627728 #OneUptime #Vulnerability

    Post summary

    The article announces the discovery of a command injection vulnerability (CVE-2026-27728) in OneUptime’s Probe server that could allow attackers to execute arbitrary OS commands and potentially take full control of the system, but it does not mention any exploit code, active attacks, or available mitigations.

    01000153
    484 followersView on X
  • ThreatCluster@threatcluster
    Patch

    CVE-2026-27728 in OneUptime allows authenticated command injection on Probe servers, enabling full takeover on versions before 10.0.7. Immediate patching advised. #Vulnerability https://threatcluster.io/cluster/oneuptime-command-injection-vulnerability-allows-full-server-1d6c627f

    Post summary

    CVE-2026-27728 is an authenticated command injection vulnerability in OneUptime Probe servers before version 10.0.7, allowing full takeover; immediate patching is advised.

    0000043
    86 followersView on X
  • ThreatSynop@ThreatSynop
    Disclosure

    🚨 OneUptime CVE-2026-27728 enables command injection for full Probe server takeover A critical bug in OneUptime’s Probe Server traceroute feature lets any authenticated project user inject shell metacharacters into a user-supplied destination, leading to OS command execution and potential full server compromise. Upgrade to OneUptime 10.0.7+ (switch to execFile) and audit monitor destinations for suspicious characters to prevent RCE. 🎯 Target: Global/Organizations using OneUptime #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cyberpress.org/oneuptime-command-injection-flaw-enables-full-server-takeover/

    Post summary

    CVE-2026-27728 is a command‑injection vulnerability in OneUptime’s Probe Server that enables OS command execution; users are advised to upgrade to 10.0.7+ and audit inputs to prevent RCE.

    0000049
    244 followersView on X
  • Karma-X@Karma_X_Inc
    Disclosure

    CVE-2026-27728 (CVSS 10): Critical Command Injection Flaw in OneUptime Probe Enables Full Server Takeover https://securityonline.info/cve-2026-27728-cvss-10-critical-command-injection-flaw-in-oneuptime-probe-enables-full-server-takeover/

    Post summary

    The article announces a critical command injection vulnerability (CVE-2026-27728) in OneUptime Probe that could allow full server takeover, with a CVSS score of 10.

    0000057
    70 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-27728 OneUptime is a solution for monitoring and managing online services. Prior to version 10.0.7, an OS command injection vulnerability in `NetworkPathMonitor.performTrac… https://www.cve.org/CVERecord?id=CVE-2026-27728 ----- Traducción: CVE-2026-27728 One… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-27728, an OS command injection vulnerability in OneUptime before v10.0.7, and provides a link to the CVE record for more details.

    0000043
    55 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27728 OneUptime is a solution for monitoring and managing online services. Prior to version 10.0.7, an OS command injection vulnerability in `NetworkPathMonitor.performTrac… https://www.cve.org/CVERecord?id=CVE-2026-27728

    Post summary

    The text announces an OS command injection vulnerability in OneUptime's NetworkPathMonitor.performTrac before v10.0.7, with no mention of PoC, exploit, or patch.

    00000201
    56.6K followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    OS Command Injection (CVE-2026-27728) found in `OneUptime` `Probe NetworkPathMonitor`. Unsanitized input in `traceroute exec()` could lead to remote code execution. Update is available. #OneUptime #InfoSec #RCE https://www.pulsepatch.io/posts/cve-2026-27728-oneuptime-os-command-injection

    Post summary

    OS Command Injection CVE-2026-27728 in OneUptime’s Probe NetworkPathMonitor allows remote code execution via unsanitized traceroute exec; a patch update is available.

    0000043
    1 followersView on X
  • CVETodo@CveTodo
    Disclosure

    **CVE-2026-27728** pertains to an **OS command injection vulnerability** in the **`NetworkPathMonitor.performTraceroute()`** function within **OneUptime** prior to version 10.0.7. This flaw allows **any authenticated project user** to execute arbitrary operating system commands on the Probe server by injecting malicious shell metacharacters into the monitor's destination field. #Cybersecurity #CVE #CriticalCVE #CriticalVulnerability #RemoteCodeExecution https://cvetodo.com/cve/CVE-2026-27728

    Post summary

    The post discloses an OS command injection vulnerability in OneUptime’s NetworkPathMonitor.performTraceroute() that allows authenticated project users to execute arbitrary OS commands on the Probe server.

    0000037
    20 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-27728 - Critical OneUptime is a solution for monitoring and managing online services. Prior to version 10.0.7, an OS command injection vulnerability in `NetworkPathMonitor.performTraceroute()` allows any ... https://www.thehackerwire.com/vulnerability/CVE-2026-27728/ https://t.co/x3phdoCeGp

    Post summary

    The post announces a critical OS command injection vulnerability in OneUptime’s NetworkPathMonitor.performTraceroute() affecting versions before 10.0.7, providing technical details but no PoC, exploit code, or evidence of active exploitation.

    0000047
    115 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphackerbayoneuptime---

Explore more