CVE-2026-30920Disclosure(hackerbay / oneuptime)

LOWCVSS 8.6 · HIGH

Signal is active with 6 mentions in latest observed window

Immediate actions

  • Patch hackerbay oneuptime systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OneUptime is a solution for monitoring and managing online services. Prior to 10.0.19, OneUptime's GitHub App callback trusts attacker-controlled state and installation_id values and updates Project.gitHubAppInstallationId with isRoot: true without validating that the caller is authorized for the target project. This allows an attacker to overwrite another project's GitHub App installation binding. Related GitHub endpoints also lack effective authorization, so a valid installation ID can be used to enumerate repositories and create CodeRepository records in an arbitrary project. This vulnerability is fixed in 10.0.19.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-345CWE-639CWE-862

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • oneuptime

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 7 signals
  • Disclosure: 4 classified signals
  • Peaked at 6 mentions on most recent observed day (2026-03-10)
  • 7 total mentions across 2 days

Affected systems

Vendors
Products
oneuptime

Deep dive

Activity timeline7 mentions / 2d
02356Mentions · 2026-03-09: 1Mentions · 2026-03-10: 6Patch / Workaround · 2026-03-10: 3Technical Details · 2026-03-09: 1Technical Details · 2026-03-10: 603-0903-10
Signal classification2 categories
Disclosure
457.1%
Patch
342.9%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-03-091
Disclosure1
2026-03-106
Disclosure3Patch3
Full discourse7 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-30920 GitHub App Authorization Bypass in OneUptime Before 10.0.19 Enabling Project Takeover https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-30920

    Post summary

    The CVE-2026-30920 vulnerability is an authorization bypass in OneUptime versions prior to 10.0.19 that permits project takeover; no PoC, exploit, or patch details are provided.

    0001038
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-30920: HIGH] OneUptime's GitHub App vulnerability in versions prior to 10.0.19 allows attackers to overwrite GitHub App installation bindings. Patched in version 10.0.19. #cybersecurity#cve,CVE-2026-30920,#cybersecurity https://cvefind.com/CVE-2026-30920

    Post summary

    OneUptime addressed CVE‑2026‑30920 by patching it in version 10.0.19, fixing a vulnerability that allowed overwriting GitHub App installation bindings; no active exploitation or PoC is mentioned.

    0000030
    601 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-30920 - High OneUptime is a solution for monitoring and managing online services. Prior to 10.0.19, OneUptime's GitHub App callback trusts attacker-controlled state and installation_id values and updates ... https://www.thehackerwire.com/vulnerability/CVE-2026-30920/ https://t.co/CT2Y47U9OC

    Post summary

    The post announces the discovery of CVE-2026-30920 in OneUptime, describing a high‑severity flaw where the GitHub App callback trusts attacker‑controlled state and installation_id values; no PoC, exploit, patch or active‑use details are provided.

    0000023
    133 followersView on X
  • Infoflowcloud@infoflowcloud
    Patch

    🚨*CVE* CVE-2026-30920 OneUptime is a solution for monitoring and managing online services. Prior to 10.0.19, OneUptime's GitHub App callback trusts attacker-controlled state and installati… https://www.cve.org/CVERecord?id=CVE-2026-30920 ----- Traducción: CVE-2026-30920 One… http://infoflow.cloud`

    Post summary

    CVE-2026-30920 exposes a flaw where a OneUptime GitHub App callback trusts attacker‑controlled state, and the issue is remedied in version 10.0.19.

    0000041
    57 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-30920 OneUptime is a solution for monitoring and managing online services. Prior to 10.0.19, OneUptime's GitHub App callback trusts attacker-controlled state and installati… https://www.cve.org/CVERecord?id=CVE-2026-30920

    Post summary

    The CVE describes a GitHub App callback issue in OneUptime that was fixed in version 10.0.19; technical details are limited and no exploitation or PoC is mentioned.

    00000193
    56.7K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-30920 - OneUptime has broken access control in GitHub App installation flow that allows unauthorized project binding Intel Report: https://ift.tt/Dm5XbR1

    Post summary

    The post announces CVE‑2026‑30920, highlighting broken access control in OneUptime’s GitHub App installation flow that permits unauthorized project binding, with no mention of patches, exploits, or PoC.

    0000038
    347 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 OneUptime, Broken Access Control, #CVE-2026-30920 (High) https://dailycve.com/oneuptime-broken-access-control-cve-2026-30920-high/

    Post summary

    The post announces a newly disclosed high‑severity CVE, CVE-2026-30920, describing it as a broken access control issue, but provides no PoC, exploit, or patch details.

    0000022
    166 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphackerbayoneuptime---

Explore more