CVE-2026-28787Disclosure(hackerbay / oneuptime)

LOWCVSS 9.0 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OneUptime is a solution for monitoring and managing online services. In version 10.0.11 and prior, the WebAuthn authentication implementation does not store the challenge on the server side. Instead, the challenge is returned to the client and accepted back from the client request body during verification. This violates the WebAuthn specification (W3C Web Authentication Level 2, §13.4.3) and allows an attacker who has obtained a valid WebAuthn assertion (e.g., via XSS, MitM, or log exposure) to replay it indefinitely, completely bypassing the second-factor authentication. No known patches are available.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287CWE-294

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • oneuptime

Threat summary

  • 7 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 6 signals
  • Disclosure: 5 classified signals
  • General: 2 classified signals
  • Peaked 2d ago at 5 mentions (2026-03-06); latest day: 1
  • 7 total mentions across 3 days

Affected systems

Vendors
Products
oneuptime

Deep dive

Activity timeline7 mentions / 3d
01345Mentions · 2026-03-06: 5Mentions · 2026-03-11: 1Mentions · 2026-03-12: 1Technical Details · 2026-03-06: 5Technical Details · 2026-03-11: 103-0603-1103-12
Signal classification2 categories
Disclosure
571.4%
General
228.6%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-065
Disclosure4General1
2026-03-111
Disclosure1
2026-03-121
General1
Full discourse7 posts
  • jk @jkmartindale
    General

    @heya_ari yeah no kidding https://nvd.nist.gov/vuln/detail/CVE-2026-28787

    Post summary

    The tweet merely links to the NVD page for CVE-2026-28787, providing no additional details about the vulnerability, exploitation, or mitigation.

    1000035
    262 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-28787 (CVSS:8.2, HIGH) is Analyzed. OneUptime is a solution for monitoring and managing online services. In version 10.0.11 and prior, the WebAuthn authenti..https://nvd.nist.gov/vuln/detail/CVE-2026-28787 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post is a brief announcement of CVE‑2026‑28787, noting its high severity, affected version of OneUptime, and linking to the NVD entry, but it provides no PoC, exploit, or patch details.

    0000018
    172 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-28787 OneUptime is a solution for monitoring and managing online services. In version 10.0.11 and prior, the WebAuthn authentication implementation does not store the chall… https://www.cve.org/CVERecord?id=CVE-2026-28787 ----- Traducción: CVE-2026-28787 One… http://infoflow.cloud`

    Post summary

    The text announces CVE-2026-28787, citing a flaw in OneUptime's WebAuthn handling, but offers only limited technical details and no exploit, mitigation, or active exploitation information.

    0000031
    56 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-28787 OneUptime is a solution for monitoring and managing online services. In version 10.0.11 and prior, the WebAuthn authentication implementation does not store the chall… https://www.cve.org/CVERecord?id=CVE-2026-28787

    Post summary

    The post briefly notes a CVE affecting OneUptime’s WebAuthn implementation, giving a minimal technical detail but no proof‑of‑concept, exploit, active usage evidence, or patch mention.

    00000176
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-28787 WebAuthn Authentication Bypass in OneUptime 10.0.11 via Challenge Replay https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-28787

    Post summary

    OneUptime 10.0.11 is vulnerable to a WebAuthn authentication bypass via challenge replay (CVE‑2026‑28787).

    0000056
    4.0K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-28787 - High OneUptime is a solution for monitoring and managing online services. In version 10.0.11 and prior, the WebAuthn authentication implementation does not store the challenge on the server side. ... https://www.thehackerwire.com/vulnerability/CVE-2026-28787/ https://t.co/LZ7nAEpSop

    Post summary

    The tweet announces CVE-2026-28787, a high‑severity WebAuthn challenge‑storage vulnerability in OneUptime versions up to 10.0.11, but does not provide a PoC, exploit, patch, or evidence of active exploitation.

    0000040
    125 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-28787 - OneUptime has WebAuthn 2FA bypass: server accepts client-supplied challenge instead of server-stored value, allowing credential replay Intel Report: https://ift.tt/x5bizXZ

    Post summary

    The text announces OneUptime’s CVE-2026-28787, a WebAuthn 2FA bypass that permits credential replay by accepting client-supplied challenges; no exploit, patch, or active exploitation is mentioned.

    0000051
    343 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphackerbayoneuptime---

Explore more