
@heya_ari yeah no kidding https://nvd.nist.gov/vuln/detail/CVE-2026-28787
Post summary
The tweet merely links to the NVD page for CVE-2026-28787, providing no additional details about the vulnerability, exploitation, or mitigation.
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
OneUptime is a solution for monitoring and managing online services. In version 10.0.11 and prior, the WebAuthn authentication implementation does not store the challenge on the server side. Instead, the challenge is returned to the client and accepted back from the client request body during verification. This violates the WebAuthn specification (W3C Web Authentication Level 2, §13.4.3) and allows an attacker who has obtained a valid WebAuthn assertion (e.g., via XSS, MitM, or log exposure) to replay it indefinitely, completely bypassing the second-factor authentication. No known patches are available.
Priority
LOW
Exploitation
NONE
PoC
YES
Patch
NONE
Momentum
STABLE
If you run products in this scope, you should treat this CVE as relevant to your environment.
| Date | Total | Labels |
|---|
| 2026-03-06 | 5 | Disclosure4General1 |
| 2026-03-11 | 1 | Disclosure1 |
| 2026-03-12 | 1 | General1 |

@heya_ari yeah no kidding https://nvd.nist.gov/vuln/detail/CVE-2026-28787
Post summary
The tweet merely links to the NVD page for CVE-2026-28787, providing no additional details about the vulnerability, exploitation, or mitigation.

CVE-2026-28787 (CVSS:8.2, HIGH) is Analyzed. OneUptime is a solution for monitoring and managing online services. In version 10.0.11 and prior, the WebAuthn authenti..https://nvd.nist.gov/vuln/detail/CVE-2026-28787 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre
Post summary
The post is a brief announcement of CVE‑2026‑28787, noting its high severity, affected version of OneUptime, and linking to the NVD entry, but it provides no PoC, exploit, or patch details.

🚨*CVE* CVE-2026-28787 OneUptime is a solution for monitoring and managing online services. In version 10.0.11 and prior, the WebAuthn authentication implementation does not store the chall… https://www.cve.org/CVERecord?id=CVE-2026-28787 ----- Traducción: CVE-2026-28787 One… http://infoflow.cloud`
Post summary
The text announces CVE-2026-28787, citing a flaw in OneUptime's WebAuthn handling, but offers only limited technical details and no exploit, mitigation, or active exploitation information.

CVE-2026-28787 OneUptime is a solution for monitoring and managing online services. In version 10.0.11 and prior, the WebAuthn authentication implementation does not store the chall… https://www.cve.org/CVERecord?id=CVE-2026-28787
Post summary
The post briefly notes a CVE affecting OneUptime’s WebAuthn implementation, giving a minimal technical detail but no proof‑of‑concept, exploit, active usage evidence, or patch mention.

CVE-2026-28787 WebAuthn Authentication Bypass in OneUptime 10.0.11 via Challenge Replay https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-28787
Post summary
OneUptime 10.0.11 is vulnerable to a WebAuthn authentication bypass via challenge replay (CVE‑2026‑28787).

🟠 CVE-2026-28787 - High OneUptime is a solution for monitoring and managing online services. In version 10.0.11 and prior, the WebAuthn authentication implementation does not store the challenge on the server side. ... https://www.thehackerwire.com/vulnerability/CVE-2026-28787/ https://t.co/LZ7nAEpSop
Post summary
The tweet announces CVE-2026-28787, a high‑severity WebAuthn challenge‑storage vulnerability in OneUptime versions up to 10.0.11, but does not provide a PoC, exploit, patch, or evidence of active exploitation.

🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-28787 - OneUptime has WebAuthn 2FA bypass: server accepts client-supplied challenge instead of server-stored value, allowing credential replay Intel Report: https://ift.tt/x5bizXZ
Post summary
The text announces OneUptime’s CVE-2026-28787, a WebAuthn 2FA bypass that permits credential replay by accepting client-supplied challenges; no exploit, patch, or active exploitation is mentioned.
1 of 1 entries
| Part | Vendor | Product | Version | Target SW | Target HW |
|---|---|---|---|---|---|
| App | hackerbay | oneuptime | - | - | - |