CVE-2026-30957Disclosure(hackerbay / oneuptime)

LOWCVSS 9.9 · CRITICAL

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch hackerbay oneuptime systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

OneUptime is a solution for monitoring and managing online services. Prior to 10.0.21, OneUptime Synthetic Monitors allow a low-privileged authenticated project user to execute arbitrary commands on the oneuptime-probe server/container. The root cause is that untrusted Synthetic Monitor code is executed inside Node's vm while live host-realm Playwright browser and page objects are exposed to it. A malicious user can call Playwright APIs on the injected browser object and cause the probe to spawn an attacker-controlled executable. This is a server-side remote code execution issue. It does not require a separate vm sandbox escape. This vulnerability is fixed in 10.0.21.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-749

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • oneuptime

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 8 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 6 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 4 mentions (2026-03-10); latest day: 2
  • 8 total mentions across 4 days

Affected systems

Vendors
Products
oneuptime

Deep dive

Activity timeline8 mentions / 4d
01234Mentions · 2026-03-10: 4Mentions · 2026-03-11: 1Mentions · 2026-03-12: 1Mentions · 2026-03-17: 2PoC Mentioned / Linked · 2026-03-10: 1Patch / Workaround · 2026-03-10: 2Patch / Workaround · 2026-03-11: 1Technical Details · 2026-03-10: 4Technical Details · 2026-03-11: 1Technical Details · 2026-03-12: 103-1003-1103-1203-17
Signal classification3 categories
Disclosure
450.0%
Patch
337.5%
General
112.5%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-03-104
Disclosure2Patch2
2026-03-111
Patch1
2026-03-121
Disclosure1
2026-03-172
Disclosure1General1
Full discourse8 posts
  • Gray Hats@the_yellow_fall
    Patch

    Two critical 10.0 CVSS flaws (CVE-2026-30956, CVE-2026-30957) in OneUptime allow full account takeovers and Server-Side RCE. Update to 10.0.21 immediately. #OneUptime #CVE #CyberSecurity #InfoSec #Vulnerability #RCE #AccountTakeover #PatchAlert #AppSec https://securityonline.info/maximum-10-0-cvss-flaws-in-oneuptime-allow-full-account-takeovers-and-rce/ https://t.co/olxDIUV3l7

    Post summary

    The tweet alerts to two CVE‑2026‑30956 and CVE‑2026‑30957 vulnerabilities in OneUptime—both CVSS 10.0—allowing full account takeover and server‑side RCE, and urges users to immediately patch to version 10.0.21.

    10063432
    10.6K followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-30957 OneUptime is a solution for monitoring and managing online services. Prior to 10.0.21, OneUptime Synthetic Monitors allow a low-privileged authenticated project user … https://www.cve.org/CVERecord?id=CVE-2026-30957 ----- Traducción: CVE-2026-30957 One… http://infoflow.cloud`

    Post summary

    The post merely references CVE‑2026‑30957 and links to its public record, without providing any exploit details, patches, or technical specifics.

    0000025
    60 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-30957 OneUptime is a solution for monitoring and managing online services. Prior to 10.0.21, OneUptime Synthetic Monitors allow a low-privileged authenticated project user … https://www.cve.org/CVERecord?id=CVE-2026-30957

    Post summary

    This post references CVE‑2026‑30957, noting that prior to version 10.0.21 OneUptime Synthetic Monitors allow a low‑privileged authenticated project user to exploit a vulnerability. No proof of concept, exploit code, or active exploitation details are provided.

    00000152
    56.8K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 OneUptime, Remote Code Execution, #CVE-2026-30957 (Critical) https://dailycve.com/oneuptime-remote-code-execution-cve-2026-30957-critical/

    Post summary

    The tweet announces the discovery of CVE-2026-30957, a Remote Code Execution vulnerability classified as Critical for OneUptime, and links to a DailyCVE article for details.

    0000020
    168 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-30957: CRITICAL] Prior to version 10.0.21, OneUptime had a remote code execution vulnerability. This flaw allowed authenticated users to run arbitrary commands on the server. Update to version 10.0...#cve,CVE-2026-30957,#cybersecurity https://cvefind.com/CVE-2026-30957

    Post summary

    The post reports that CVE-2026-30957 is a critical remote code execution flaw affecting authenticated users in OneUptime before version 10.0.21, and it urges users to upgrade to the patched version 10.0 to mitigate the vulnerability.

    0000040
    601 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-30957 - Critical OneUptime is a solution for monitoring and managing online services. Prior to 10.0.21, OneUptime Synthetic Monitors allow a low-privileged authenticated project user to execute arbitrary ... https://www.thehackerwire.com/vulnerability/CVE-2026-30957/ https://t.co/TAwlRQVPUP

    Post summary

    A new critical CVE‑2026‑30957 affecting OneUptime lets low‑privileged authenticated users execute arbitrary code; the tweet offers no PoC, exploit code, or patch information.

    0000023
    133 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-30957: OneUptime Synthetic Monitor RCE ... Playwright browser object exposure in Node.js vm bypasses sandbox entirely - low-priv users spawn arbitrary executables... https://zerodaysignal.com/vulnerability/CVE-2026-30957 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    A newly disclosed RCE vulnerability (CVE‑2026‑30957) in OneUptime Synthetic Monitor that exploits Playwright’s browser object exposure to bypass the Node.js VM sandbox, enabling low‑privileges users to execute arbitrary code; a vulnerability page is provided for more details.

    0000037
    143 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    A critical RCE (CVE-2026-30957) affects `OneUptime Common` (`@oneuptime/common`) via exposed `Playwright` object in `Synthetic Monitors`. Update to 10.0.21 or later to mitigate. #infosec #RCE #nodejs https://www.pulsepatch.io/posts/cve-2026-30957-oneuptime-common-rce-playwright

    Post summary

    The post announces a critical RCE in OneUptime Common (CVE-2026-30957) and recommends upgrading to version 10.0.21 or newer to mitigate.

    0000036
    1 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphackerbayoneuptime---

Explore more