Remote Command Execution Vulnerability in OneUptime Monitoring Platform
CVE-2026-33396
10CRITICAL
What is CVE-2026-33396?
A vulnerability in OneUptime, an open-source monitoring and observability platform, allows low-privileged authenticated users to execute arbitrary commands on the Probe container or host. This occurs through a flaw in the handling of Synthetic Monitor Playwright scripts executed within the platform. Specifically, the incomplete denylist in the VMRunner.runCodeInNodeVM sandbox permits access to sensitive properties and methods, enabling exploitation via commands that can spawn arbitrary processes. OneUptime version 10.0.35 addresses this vulnerability with a patch.
Affected Version(s)
oneuptime < 10.0.35
