Access Control Flaw in OneUptime Affects User Account Creation
CVE-2025-65966
8.8HIGH
What is CVE-2025-65966?
A security vulnerability in OneUptime version 9.0.5598 allows low-permission users to create new accounts via direct API requests. This bypasses the intended user interface and poses a risk to the integrity of user management within the system. The issue has been addressed in version 9.1.0, enhancing the security measures to prevent unauthorized account access.
Affected Version(s)
oneuptime = 9.0.5598
