CVE-2026-30921Disclosure(hackerbay / oneuptime)

LOWCVSS 9.9 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch hackerbay oneuptime systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OneUptime is a solution for monitoring and managing online services. Prior to 10.0.20, OneUptime Synthetic Monitors allow low-privileged project users to submit custom Playwright code that is executed on the oneuptime-probe service. In the current implementation, this untrusted code is run inside Node's vm and is given live host Playwright objects such as browser and page. This creates a distinct server-side RCE primitive: the attacker does not need the classic this.constructor.constructor(...) sandbox escape. Instead, the attacker can directly use the injected Playwright browser object to reach browser.browserType().launch(...) and spawn an arbitrary executable on the probe host/container. This vulnerability is fixed in 10.0.20.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-749

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • oneuptime

Threat summary

  • Patch or workaround signal is available
  • 10 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 9 signals
  • Disclosure: 9 classified signals
  • Peaked 2d ago at 7 mentions (2026-03-10); latest day: 1
  • 10 total mentions across 4 days

Affected systems

Vendors
Products
oneuptime

Deep dive

Activity timeline10 mentions / 4d
02457Mentions · 2026-03-09: 1Mentions · 2026-03-10: 7Mentions · 2026-03-12: 1Mentions · 2026-03-29: 1Patch / Workaround · 2026-03-29: 1Technical Details · 2026-03-09: 1Technical Details · 2026-03-10: 6Technical Details · 2026-03-12: 1Technical Details · 2026-03-29: 103-0903-1003-1203-29
Signal classification2 categories
Disclosure
990.0%
Patch
110.0%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-03-091
Disclosure1
2026-03-107
Disclosure7
2026-03-121
Disclosure1
2026-03-291
Patch1
Full discourse10 posts
  • maruomosquit@maru1151157
    Patch

    🚨 CVE-2026-30921 (CVSS: 9.9) 10.0.20以前のOneUptime Synthetic Monitorsで、低権限ユーザーによるPlaywrightコード送信が可能。不正コードがNode vm内で実行され、browserオブジェクトを介して任意実行可能(RCE)。10.0.20で修正。 https://maruomosquit.com/vulnerability/CVE-2026-30921/ #脆弱性 #セキュリティ

    Post summary

    CVE-2026-30921 enables remote code execution via Playwright code sent by low‑privileged users; the vulnerability is fixed in OneUptime 10.0.20.

    00030198
    1.4K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 https://dailycve.com/oneuptime-remote-code-execution-#cve-2026-30921-critical-2/ Nuxt, URI Scheme Bypass, CVE-2024-34344 (Critical)

    Post summary

    The tweet links to a DailyCVE article announcing a remote code execution vulnerability (CVE‑2026‑30921) and a URI scheme bypass in Nuxt (CVE‑2024‑34344), but it offers only the basic classification without detailed exploit or mitigation information.

    0000048
    168 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-30921: CRITICAL] Prior to version 10.0.20, OneUptime had a vulnerability allowing low-privileged users to execute untrusted Playwright code on the server-side, enabling remote code execution. Updat...#cve,CVE-2026-30921,#cybersecurity https://cvefind.com/CVE-2026-30921

    Post summary

    The post announces the CVE‑2026‑30921 vulnerability in OneUptime, noting that low‑privileged users can run untrusted Playwright code on the server, resulting in remote code execution.

    0000029
    601 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-30921 OneUptime Synthetic Monitors Remote Code Execution via Playwright Browser Object https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-30921

    Post summary

    The text announces a new CVE—CVE-2026-30921—reporting a remote code execution flaw in OneUptime Synthetic Monitors via a Playwright browser object, but provides no PoC, exploit code, or patch information.

    0000030
    4.0K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-30921 - Critical OneUptime is a solution for monitoring and managing online services. Prior to 10.0.20, OneUptime Synthetic Monitors allow low-privileged project users to submit custom Playwright code tha... https://www.thehackerwire.com/vulnerability/CVE-2026-30921/ https://t.co/MJZm7vQi6w

    Post summary

    A new critical vulnerability (CVE‑2026‑30921) in OneUptime allows low‑privileged users to run arbitrary Playwright scripts via Synthetic Monitors, potentially leading to code execution. No active exploitation, patches, or PoC details are cited in the excerpt.

    0000027
    133 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-30921 OneUptime is a solution for monitoring and managing online services. Prior to 10.0.20, OneUptime Synthetic Monitors allow low-privileged project users to submit custo… https://www.cve.org/CVERecord?id=CVE-2026-30921 ----- Traducción: CVE-2026-30921 One… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑30921, noting that before OneUptime 10.0.20, low‑privileged project users could submit custom code via Synthetic Monitors, but no PoC, exploit, patch, or active exploitation details are provided.

    0000032
    57 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-30921 OneUptime is a solution for monitoring and managing online services. Prior to 10.0.20, OneUptime Synthetic Monitors allow low-privileged project users to submit custo… https://www.cve.org/CVERecord?id=CVE-2026-30921

    Post summary

    The CVE-2026-30921 record indicates that OneUptime's Synthetic Monitors allow low‑privileged users to submit custom content, suggesting a potential vulnerability. No proof‑of‑concept, exploit code, active exploitation, patch, or false‑positive claim is provided.

    00000193
    56.7K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 OneUptime, Remote Code Execution, #CVE-2026-30921 (Critical) https://dailycve.com/oneuptime-remote-code-execution-cve-2026-30921-critical/

    Post summary

    The text announces the discovery of a critical remote code execution vulnerability (CVE-2026-30921) in OneUptime, but provides no additional details or evidence of exploitation.

    0000042
    167 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-30921 - OneUptime Synthetic Monitor RCE via exposed Playwright browser object Intel Report: https://ift.tt/dcjpNyP

    Post summary

    An advisory alerts to CVE-2026-30921—a remote code execution flaw in OneUptime Synthetic Monitor involving an exposed Playwright browser object. No proof of concept, exploit code, or patch details are provided.

    0000046
    347 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-30921: OneUptime Synthetic Monitor RCE ... Playwright browser object injection bypasses Node.js vm sandbox entirely - no constructor escapes needed when you can s... https://zerodaysignal.com/vulnerability/CVE-2026-30921 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The text announces a new RCE vulnerability (CVE-2026-30921) in OneUptime Synthetic Monitor, describing the technical bypass technique but lacking PoC, exploit code, or patch details.

    0000065
    140 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphackerbayoneuptime---

Explore more