CVE-2026-28787 affects OneUptime versions 10.0.11 and prior, where a flaw in the WebAuthn implementation allows for replay attacks. The server fails to store the challenge, instead returning it to the client, enabling an attacker to reuse a valid WebAuthn assertion indefinitely. This vulnerability carries a high CVSS score of 8.2 due to its network attack vector, high impact on confidentiality and integrity, and low privileges required, though it has high attack complexity. There are no known patches, active exploits, or public exploit code available, but it has garnered some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 10.0.11CPE matchmatch criteria | cpe:2.3:a:hackerbay:oneuptime:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.4 Reddit, 1.2 Bluesky, 0.8 Mastodon, and 2.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.8 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.