Remote Command Execution Vulnerability in OneUptime Monitoring Platform
CVE-2026-33396

10CRITICAL

Key Information:

Vendor

Oneuptime

Status
Vendor
CVE Published:
26 March 2026

What is CVE-2026-33396?

A vulnerability in OneUptime, an open-source monitoring and observability platform, allows low-privileged authenticated users to execute arbitrary commands on the Probe container or host. This occurs through a flaw in the handling of Synthetic Monitor Playwright scripts executed within the platform. Specifically, the incomplete denylist in the VMRunner.runCodeInNodeVM sandbox permits access to sensitive properties and methods, enabling exploitation via commands that can spawn arbitrary processes. OneUptime version 10.0.35 addresses this vulnerability with a patch.

Affected Version(s)

oneuptime < 10.0.35

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.