Vulmon Vulnerability Feed@VulmonFeedsDisclosure
The CVE-2026-30920 vulnerability is an authorization bypass in OneUptime versions prior to 10.0.19 that permits project takeover; no PoC, exploit, or patch details are provided.
CVEFind.com@CveFindComPatch
OneUptime addressed CVE‑2026‑30920 by patching it in version 10.0.19, fixing a vulnerability that allowed overwriting GitHub App installation bindings; no active exploitation or PoC is mentioned.
The Hacker Wire@TheHackerWireDisclosure
The post announces the discovery of CVE-2026-30920 in OneUptime, describing a high‑severity flaw where the GitHub App callback trusts attacker‑controlled state and installation_id values; no PoC, exploit, patch or active‑use details are provided.
Infoflowcloud@infoflowcloudPatch
CVE-2026-30920 exposes a flaw where a OneUptime GitHub App callback trusts attacker‑controlled state, and the issue is remedied in version 10.0.19.
CVE@CVEnewPatch
The CVE describes a GitHub App callback issue in OneUptime that was fixed in version 10.0.19; technical details are limited and no exploitation or PoC is mentioned.
CyberDudeBivash® | Global Cybersecurity Company@cyberbivashDisclosure
The post announces CVE‑2026‑30920, highlighting broken access control in OneUptime’s GitHub App installation flow that permits unauthorized project binding, with no mention of patches, exploits, or PoC.
DailyCVE@dailycveDisclosure
The post announces a newly disclosed high‑severity CVE, CVE-2026-30920, describing it as a broken access control issue, but provides no PoC, exploit, or patch details.