SQL Injection Vulnerability in OneUptime Monitoring Service
CVE-2026-32306
10CRITICAL
What is CVE-2026-32306?
OneUptime, an online services monitoring tool, has a critical SQL injection vulnerability affecting versions prior to 10.0.23. The telemetry aggregation API inadequately handles user-controlled parameters, allowing authenticated users to inject arbitrary SQL commands into ClickHouse queries. This lack of input validation and absence of parameterized queries can lead to unauthorized database access, manipulation of data, and potential remote code execution through ClickHouse functions. Users are urged to update to version 10.0.23 or later to mitigate these risks.
Affected Version(s)
oneuptime < 10.0.23
