CVE-2026-35053Disclosure(hackerbay / oneuptime)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch hackerbay oneuptime systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, the Worker service's ManualAPI exposes workflow execution endpoints (GET /workflow/manual/run/:workflowId and POST /workflow/manual/run/:workflowId) without any authentication middleware. An attacker who can obtain or guess a workflow ID can trigger arbitrary workflow execution with attacker-controlled input data, enabling JavaScript code execution, notification abuse, and data manipulation. This issue has been patched in version 10.0.42.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • oneuptime

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-04-02); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
oneuptime

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-02: 1Mentions · 2026-04-03: 1Mentions · 2026-04-14: 1Patch / Workaround · 2026-04-14: 1Technical Details · 2026-04-02: 1Technical Details · 2026-04-03: 1Technical Details · 2026-04-14: 104-0204-0304-14
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-04-021
Disclosure1
2026-04-031
Disclosure1
2026-04-141
Patch1
Full discourse3 posts
  • Giuseppe Paternicola@giuseppe_1337
    Patch

    🚨 CRITICAL: CVE-2026-35053 (CVSS 9.8) OneUptime <10.0.42 exposes unauthenticated workflow execution endpoints. Attackers can execute arbitrary JavaScript, manipulate data, abuse notifications. Patch to 10.0.42 immediately. #CVE #PatchNow #ThreatIntel https://t.co/NaLK1VjhP4

    Post summary

    Alert warns of a critical CVE-2026-35053 in OneUptime allowing unauthenticated JavaScript execution, and urges an immediate upgrade to version 10.0.42 for remediation.

    0000037
    25 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-35053 OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, the Worker service's ManualAPI exposes workflow execution endpoints (GET … https://www.cve.org/CVERecord?id=CVE-2026-35053

    Post summary

    The post announces CVE‑2026‑35053, noting that the OneUptime Worker service’s ManualAPI exposed workflow execution endpoints before version 10.0.42, but provides no further details on exploits, patches, or active use.

    00000140
    56.9K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-35053: OneUptime: Unauthenticated Workf... Unauthenticated workflow execution with arbitrary JS code injection - just enumerate workflow IDs and own the entire mo... https://zerodaysignal.com/vulnerability/CVE-2026-35053 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE‑2026‑35053—a vulnerability in OneUptime that permits unauthenticated execution of arbitrary JavaScript through workflow enumeration—but offers no Proof of Concept, exploit code, or patch information.

    0000056
    193 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphackerbayoneuptime---

Explore more