Gray Hats@the_yellow_fallPatch
The text reports two critical CVEs (CVE‑2026‑30956 and CVE‑2026‑30957) that enable account takeovers and SSRCE in OneUptime and urges users to update to version 10.0.21.
Infoflowcloud@infoflowcloudDisclosure
The text discloses CVE-2026‑30956, noting that a low‑privileged user can bypass authorization and tenant isolation in OneUptime versions prior to 10.0.21.
CVE@CVEnewDisclosure
The post discloses a low‑privileged bypass vulnerability in OneUptime versions before 10.0.21 that allows users to circumvent authorization and tenant isolation, with a link to the official CVE record.
DailyCVE@dailycveDisclosure
Announcement of a critical authorization bypass vulnerability (CVE‑2026‑30956) in OneUptime with no further technical, exploit, or mitigation details provided.
CVEFind.com@CveFindComDisclosure
CVE-2026-30956 exposes an authorization bypass in OneUptime v10.0.20, allowing attackers to access data and takeover accounts, and users are urged to upgrade to a patched version.
0day Signal@0dayPublishingDisclosure
The tweet announces the disclosure of CVE-2026-30956, highlighting an authorization bypass in OneUptime that lets attackers read all customer data via client-controlled headers, but does not mention a PoC, active exploitation, or mitigation.
The Hacker Wire@TheHackerWireDisclosure
The text announces a critical authorization bypass (CVE‑2026‑30956) in OneUptime versions prior to 10.0.21 that allows low‑privileged users to compromise tenant isolation.
PulsePatch.io@pulsepatchioPatch
A critical authorization bypass (CVE‑2026‑30956) in OneUptime’s @oneuptime/common has been fixed in v10.0.21; users are urged to upgrade to remediate the vulnerability.