CVE-2026-33142General(hackerbay / oneuptime)

LOWCVSS 8.1 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OneUptime is a solution for monitoring and managing online services. Prior to version 10.0.34, the fix for CVE-2026-32306 (ClickHouse SQL injection via aggregate query parameters) added column name validation to the _aggregateBy method but did not apply the same validation to three other query construction paths in StatementGenerator. The toSortStatement, toSelectStatement, and toGroupByStatement methods accept user-controlled object keys from API request bodies and interpolate them as ClickHouse Identifier parameters without verifying they correspond to actual model columns. ClickHouse Identifier parameters are substituted directly into queries without escaping, so an attacker who can reach any analytics list or aggregate endpoint can inject arbitrary SQL through crafted sort, select, or groupBy keys. This issue has been patched in version 10.0.34.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • oneuptime

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • General: 3 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-03-21)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
oneuptime

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-20: 1Mentions · 2026-03-21: 203-2003-21
Signal classification1 categories
General
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-201
General1
2026-03-212
General2
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-33142 OneUptime is a solution for monitoring and managing online services. Prior to version 10.0.34, the fix for CVE-2026-32306 (ClickHouse SQL injection via aggregate quer… https://www.cve.org/CVERecord?id=CVE-2026-33142 ----- Traducción: CVE-2026-33142 One… http://infoflow.cloud`

    Post summary

    The tweet references CVE-2026‑33142 in the context of the OneUptime product but offers no details about exploits, patches, or active use, merely linking to the CVE record.

    0000041
    61 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-33142 OneUptime is a solution for monitoring and managing online services. Prior to version 10.0.34, the fix for CVE-2026-32306 (ClickHouse SQL injection via aggregate quer… https://www.cve.org/CVERecord?id=CVE-2026-33142

    Post summary

    The text merely lists CVE‑2026‑33142 and a link to its record, offering no additional details, evidence of exploitation, or patch information.

    00000189
    56.8K followersView on X
  • The Hacker Wire@TheHackerWire
    General

    🟠 CVE-2026-33142 - High OneUptime is a solution for monitoring and managing online services. Prior to version 10.0.34, the fix for CVE-2026-32306 (ClickHouse SQL injection via aggregate query parameters) added colum... https://www.thehackerwire.com/vulnerability/CVE-2026-33142/ https://t.co/uue75vg6yl

    Post summary

    The tweet references a newly disclosed vulnerability CVE-2026-33142 in OneUptime and links to an article, but provides no technical or exploit details.

    0000056
    138 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphackerbayoneuptime---

Explore more