CVE-2026-30956Disclosure(hackerbay / oneuptime)

LOWCVSS 9.9 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch hackerbay oneuptime systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OneUptime is a solution for monitoring and managing online services. Prior to 10.0.21, a low‑privileged user can bypass authorization and tenant isolation in OneUptime v10.0.20 and earlier by sending a forged is-multi-tenant-query header together with a controlled projectid header. Because the server trusts this client-supplied header, internal permission checks in BasePermission are skipped and tenant scoping is disabled. This allows attackers to access project data belonging to other tenants, read sensitive User fields via nested relations, leak plaintext resetPasswordToken, and reset the victim’s password and fully take over the account. This results in cross‑tenant data exposure and full account takeover. This vulnerability is fixed in 10.0.21.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-285CWE-862

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • oneuptime

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 7 signals
  • Disclosure: 6 classified signals
  • Peaked 3d ago at 4 mentions (2026-03-10); latest day: 2
  • 8 total mentions across 4 days

Affected systems

Vendors
Products
oneuptime

Deep dive

Activity timeline8 mentions / 4d
01234Mentions · 2026-03-10: 4Mentions · 2026-03-11: 1Mentions · 2026-03-12: 1Mentions · 2026-03-17: 2Patch / Workaround · 2026-03-10: 2Patch / Workaround · 2026-03-11: 1Technical Details · 2026-03-10: 4Technical Details · 2026-03-11: 1Technical Details · 2026-03-17: 203-1003-1103-1203-17
Signal classification2 categories
Disclosure
675.0%
Patch
225.0%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-03-104
Disclosure3Patch1
2026-03-111
Patch1
2026-03-121
Disclosure1
2026-03-172
Disclosure2
Full discourse8 posts
  • Gray Hats@the_yellow_fall
    Patch

    Two critical 10.0 CVSS flaws (CVE-2026-30956, CVE-2026-30957) in OneUptime allow full account takeovers and Server-Side RCE. Update to 10.0.21 immediately. #OneUptime #CVE #CyberSecurity #InfoSec #Vulnerability #RCE #AccountTakeover #PatchAlert #AppSec https://securityonline.info/maximum-10-0-cvss-flaws-in-oneuptime-allow-full-account-takeovers-and-rce/ https://t.co/olxDIUV3l7

    Post summary

    The text reports two critical CVEs (CVE‑2026‑30956 and CVE‑2026‑30957) that enable account takeovers and SSRCE in OneUptime and urges users to update to version 10.0.21.

    10063432
    10.6K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-30956 OneUptime is a solution for monitoring and managing online services. Prior to 10.0.21, a low‑privileged user can bypass authorization and tenant isolation in OneUptim… https://www.cve.org/CVERecord?id=CVE-2026-30956 ----- Traducción: CVE-2026-30956 One… http://infoflow.cloud`

    Post summary

    The text discloses CVE-2026‑30956, noting that a low‑privileged user can bypass authorization and tenant isolation in OneUptime versions prior to 10.0.21.

    0000026
    60 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-30956 OneUptime is a solution for monitoring and managing online services. Prior to 10.0.21, a low‑privileged user can bypass authorization and tenant isolation in OneUptim… https://www.cve.org/CVERecord?id=CVE-2026-30956

    Post summary

    The post discloses a low‑privileged bypass vulnerability in OneUptime versions before 10.0.21 that allows users to circumvent authorization and tenant isolation, with a link to the official CVE record.

    00000161
    56.8K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 OneUptime, Authorization Bypass, #CVE-2026-30956 (Critical) https://dailycve.com/oneuptime-authorization-bypass-cve-2026-30956-critical/

    Post summary

    Announcement of a critical authorization bypass vulnerability (CVE‑2026‑30956) in OneUptime with no further technical, exploit, or mitigation details provided.

    0000026
    168 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-30956: CRITICAL] Stay vigilant against cyber threats! A vulnerability in OneUptime v10.0.20 allows attackers to bypass authorization, access sensitive data, and take over accounts. Update to v10.0....#cve,CVE-2026-30956,#cybersecurity https://cvefind.com/CVE-2026-30956

    Post summary

    CVE-2026-30956 exposes an authorization bypass in OneUptime v10.0.20, allowing attackers to access data and takeover accounts, and users are urged to upgrade to a patched version.

    0000056
    601 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-30956: OneUptime has authorization bypa... Client-controlled headers bypassing tenant isolation? OneUptime just handed attackers the keys to every customer's data... https://zerodaysignal.com/vulnerability/CVE-2026-30956 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces the disclosure of CVE-2026-30956, highlighting an authorization bypass in OneUptime that lets attackers read all customer data via client-controlled headers, but does not mention a PoC, active exploitation, or mitigation.

    0000048
    142 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-30956 - Critical OneUptime is a solution for monitoring and managing online services. Prior to 10.0.21, a low‑privileged user can bypass authorization and tenant isolation in OneUptime v10.0.20 and earl... https://www.thehackerwire.com/vulnerability/CVE-2026-30956/ https://t.co/Y5PKdiG5Zj

    Post summary

    The text announces a critical authorization bypass (CVE‑2026‑30956) in OneUptime versions prior to 10.0.21 that allows low‑privileged users to compromise tenant isolation.

    0000029
    133 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    A critical authorization bypass (CVE-2026-30956) in `@oneuptime/common` affects `OneUptime` instances, leading to cross-tenant data exposure and potential account takeover. Upgrade to v10.0.21. #infosec #cybersecurity #vulnerability https://www.pulsepatch.io/posts/cve-2026-30956-oneuptime-auth-bypass

    Post summary

    A critical authorization bypass (CVE‑2026‑30956) in OneUptime’s @oneuptime/common has been fixed in v10.0.21; users are urged to upgrade to remediate the vulnerability.

    0000036
    1 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphackerbayoneuptime---

Explore more