CVE-2026-27574 is a critical remote code execution (RCE) vulnerability affecting OneUptime versions 9.5.13 and below. The flaw stems from the custom JavaScript monitor feature, which improperly uses Node.js's node:vm module, allowing for trivial sandbox escape and full access to the underlying process. This enables an unauthenticated attacker, even with the lowest role, to achieve full cluster compromise within approximately 30 seconds due to the probe running with host networking and holding sensitive credentials. The vulnerability has a CVSS score of 9.9 (CRITICAL) due to its network attack vector, low attack complexity, and complete compromise of confidentiality, integrity, and availability. There is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not listed on the CISA KEV or Hot List, though it has received some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.0.5CPE matchmatch criteria | cpe:2.3:a:hackerbay:oneuptime:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.