CVE-2026-30958Disclosure(hackerbay / oneuptime)

LOWCVSS 8.6 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

OneUptime is a solution for monitoring and managing online services. Prior to 10.0.21, an unauthenticated path traversal in the /workflow/docs/:componentName endpoint allows reading arbitrary files from the server filesystem. The componentName route parameter is concatenated directly into a file path passed to res.sendFile() in orker/FeatureSet/Workflow/Index.ts with no sanitization or authentication middleware. This vulnerability is fixed in 10.0.21.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • oneuptime

Threat summary

  • Public PoC is present in monitored signal
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 2 mentions (2026-03-17); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
oneuptime

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-12: 1Mentions · 2026-03-17: 2Mentions · 2026-06-30: 1PoC Mentioned / Linked · 2026-06-30: 1Technical Details · 2026-03-12: 1Technical Details · 2026-03-17: 2Technical Details · 2026-06-30: 103-1203-1706-30
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-121
Disclosure1
2026-03-172
Disclosure2
2026-06-301
Disclosure1
Full discourse4 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-30958 - high 🚨 OneUptime < 10.0.21 - Path Traversal > OneUptime < 10.0.21 contains a path traversal caused by unsanitized componentName par... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-30958 @pdnuclei #NucleiTemplates #cve

    Post summary

    The post announces CVE-2026-30958 as a high‑severity path traversal flaw in OneUptime versions below 10.0.21, citing an unsanitized componentName parameter, and links to a Project Discovery resource that likely includes a Nuclei template for detection.

    00000323
    963 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-30958 OneUptime is a solution for monitoring and managing online services. Prior to 10.0.21, an unauthenticated path traversal in the /workflow/docs/:componentName endpoint… https://www.cve.org/CVERecord?id=CVE-2026-30958 ----- Traducción: CVE-2026-30958 One… http://infoflow.cloud`

    Post summary

    The tweet references CVE-2026-30958, a path‑traversal issue in OneUptime before 10.0.21, and links to the CVE record; no exploits, patches, or active usage mentioned.

    0000025
    60 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-30958 OneUptime is a solution for monitoring and managing online services. Prior to 10.0.21, an unauthenticated path traversal in the /workflow/docs/:componentName endpoint… https://www.cve.org/CVERecord?id=CVE-2026-30958

    Post summary

    The statement announces CVE‑2026‑30958 as an unauthenticated path traversal in OneUptime prior to 10.0.21, offering technical details but no evidence of exploitation, mitigation, or falsification.

    00000161
    56.8K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 OneUptime, Path Traversal, #CVE-2026-30958 (HIGH) https://dailycve.com/oneuptime-path-traversal-cve-2026-30958-high/

    Post summary

    A path traversal vulnerability (CVE-2026-30958) in OneUptime has been disclosed with a high severity rating; no exploit or mitigation details are provided in the text.

    0000020
    167 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphackerbayoneuptime---

Explore more