Open-source Monitoring Platform Vulnerability in OneUptime
CVE-2026-35053
9.2CRITICAL
What is CVE-2026-35053?
An improper authentication vulnerability exists in OneUptime, an open-source monitoring and observability platform, prior to version 10.0.42. The Worker service's ManualAPI exposes critical workflow execution endpoints without necessary authentication checks. This oversight allows an attacker to exploit the API by obtaining or guessing a workflow ID, which can lead to unauthorized execution of workflows. Such exploitation could facilitate the running of arbitrary JavaScript code, manipulation of data, and even notification abuses, posing significant security risks. The vulnerability has been addressed in the release of version 10.0.42.
Affected Version(s)
oneuptime < 10.0.42
