OneUptime是OneUptime开源的一个全面的解决方案。用于监控和管理您的在线服务。 OneUptime 10.0.42之前版本存在安全漏洞,该漏洞源于多个通知API端点未注册身份验证中间件,结合公共状态页面API的projectId泄露,可能导致未经身份验证的攻击者购买电话号码并删除所有现有警报号码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-34758 | 9.1 CRITICAL | OneUptime: Missing Authentication on Notification Endpoints |
| CVE-2026-34840 | 8.1 HIGH | OneUptime SSO: Multi-Assertion Identity Injection via Decoupled Signature Verification |
| CVE-2026-35053 | OneUptime: Unauthenticated Workflow Execution via ManualAPI |
No comments yet