SQL Injection Vulnerability in OneUptime Monitoring Service
CVE-2026-32306

10CRITICAL

Key Information:

Vendor

Oneuptime

Status
Vendor
CVE Published:
12 March 2026

What is CVE-2026-32306?

OneUptime, an online services monitoring tool, has a critical SQL injection vulnerability affecting versions prior to 10.0.23. The telemetry aggregation API inadequately handles user-controlled parameters, allowing authenticated users to inject arbitrary SQL commands into ClickHouse queries. This lack of input validation and absence of parameterized queries can lead to unauthorized database access, manipulation of data, and potential remote code execution through ClickHouse functions. Users are urged to update to version 10.0.23 or later to mitigate these risks.

Affected Version(s)

oneuptime < 10.0.23

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.