CVE-2026-33396Disclosure(hackerbay / oneuptime)

LOWCVSS 9.9 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch hackerbay oneuptime systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.35, a low-privileged authenticated user (ProjectMember) can achieve remote command execution on the Probe container/host by abusing Synthetic Monitor Playwright script execution. Synthetic monitor code is executed in VMRunner.runCodeInNodeVM with a live Playwright page object in context. The sandbox relies on a denylist of blocked properties/methods, but it is incomplete. Specifically, _browserType and launchServer are not blocked, so attacker code can traverse `page.context().browser()._browserType.launchServer(...)` and spawn arbitrary processes. Version 10.0.35 contains a patch.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78CWE-184CWE-693

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • oneuptime

Threat summary

  • Patch or workaround signal is available
  • 9 mentions across 4 observed days
  • Momentum state: declining

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 8 signals
  • Disclosure: 5 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 6 mentions (2026-03-26); latest day: 1
  • 9 total mentions across 4 days

Affected systems

Vendors
Products
oneuptime

Deep dive

Activity timeline9 mentions / 4d
02356Mentions · 2026-03-26: 6Mentions · 2026-03-27: 1Mentions · 2026-03-28: 1Mentions · 2026-03-29: 1Patch / Workaround · 2026-03-26: 3Patch / Workaround · 2026-03-28: 1Technical Details · 2026-03-26: 6Technical Details · 2026-03-28: 1Technical Details · 2026-03-29: 103-2603-2703-2803-29
Signal classification3 categories
Disclosure
555.6%
Patch
333.3%
General
111.1%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-03-266
Disclosure3Patch3
2026-03-271
General1
2026-03-281
Disclosure1
2026-03-291
Disclosure1
Full discourse9 posts
  • maruomosquit@maru1151157
    Disclosure

    🚨 CVE-2026-33396 (CVSS: 9.9) 2026-33396: OneUptime v10.0.35以前、ProjectMemberはSynthetic Monitor Playwrightスクリプトを悪用し、Probeコンテナ/ホストにリモートコマンド実行可能。サンドボックスのdenylistが不完全で、_browserType.launchServerを介して任意プロセスを生成可能。バージョン10.0.35で修正。 https://maruomosquit.com/vulnerability/CVE-2026-33396/ #脆弱性 #セキュリティ

    Post summary

    The post discloses a high‑severity remote code execution vulnerability in OneUptime versions before 10.0.35, details how Playwright scripts can be abused, notes the issue is fixed in v10.0.35, and links to a vulnerability page for more information.

    0001065
    1.4K followersView on X
  • White Rabbitx@TheRabbitPy
    Patch

    🚨 CVE-2026-33396 (CVSS 9.9 Critical): Synthetic Monitoring Playwright sandbox RCE via OS command injection. Incomplete denylist allows full compromise. Patch immediately! https://nvd.nist.gov/vuln/detail/CVE-2026-33396

    Post summary

    CVE‑2026‑33396 is a critical OS command injection vulnerability (CVSS 9.9) in Synthetic Monitoring Playwright sandbox, allowing full compromise; immediate patching is required.

    1000053
    492 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33396 OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.35, a low-privileged authenticated user (ProjectMember) can achieve remote co… https://www.cve.org/CVERecord?id=CVE-2026-33396

    Post summary

    The tweet announces CVE‑2026‑33396, noting that a low‑privileged authenticated user in OneUptime prior to v10.0.35 can achieve remote exploitation, but no PoC, exploit code, or patch is mentioned.

    0000098
    56.9K followersView on X
  • CTIWatch@ctiwatchcloud
    General

    🔍 Today's Top Vulnerabilities 🔴 CVE-2026-33494 | CVSS 10.0 🔴 CVE-2026-33897 | CVSS 9.9 🔴 CVE-2026-33396 | CVSS 9.9 🔗 http://ctiwatch.cloud/vulnerabilities #CVE #Vulnerability #ThreatIntel

    Post summary

    The post announces three high‑CVSS CVEs and links to a vulnerabilities page, but it provides no PoC, exploit, mitigation, or detailed technical information.

    0000034
    5.6K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-33396 - Critical OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.35, a low-privileged authenticated user (ProjectMember) can achieve remote command execution on th... https://www.thehackerwire.com/vulnerability/CVE-2026-33396/ https://t.co/JBb8drQd8Q

    Post summary

    The text announces CVE‑2026‑33396, a critical remote command execution flaw for low‑privileged users in OneUptime versions below 10.0.35, without providing PoC, exploit code, or patch details.

    0000045
    163 followersView on X
  • White Rabbitx@TheRabbitPy
    Patch

    🚨 Today's top CVE: CVE-2026-33396 (CVSS 9.9 Critical) - OS Command Injection in Synthetic Monitor's Playwright sandbox. Allows full RCE via incomplete denylist. Patch ASAP if using it! Published Mar 26, 2026. https://nvd.nist.gov/vuln/detail/CVE-2026-33396

    Post summary

    The post announces a critical OS command injection vulnerability (CVE-2026-33396) with an immediate patch recommendation.

    0000033
    492 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-33396 - OneUptime has sandbox escape in Synthetic Monitor Playwright runtime allows project members to execute arbitrary commands on Probe Intel Report: https://ift.tt/BIUnHFZ

    Post summary

    The tweet announces CVE-2026-33396, revealing a sandbox escape flaw in OneUptime's Synthetic Monitor Playwright runtime that permits arbitrary command execution on the Probe, with no mention of patches, exploits, or active exploitation.

    0000031
    285 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-33396: CRITICAL] Vulnerability alert: OneUptime platform < 10.0.35 allows remote command execution by low-privileged users. Update to version 10.0.35 to patch this security flaw.#cve,CVE-2026-33396,#cybersecurity https://cvefind.com/CVE-2026-33396

    Post summary

    The post alerts to a critical remote command execution vulnerability in OneUptime versions below 10.0.35 and directs users to update to 10.0.35 to mitigate the risk.

    0000063
    606 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-33396: OneUptime has sandbox escape in ... Denylist sandboxes are jokes—Playwright's `_browserType.launchServer()` bypass turns monitoring scripts into RCE goldmi... https://zerodaysignal.com/vulnerability/CVE-2026-33396 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE-2026-33396, noting a sandbox escape vulnerability in Playwright that can lead to remote code execution via monitoring scripts.

    0000086
    169 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphackerbayoneuptime---

Explore more