CVE-2026-30957 is a critical server-side remote code execution vulnerability affecting OneUptime versions prior to 10.0.21. This flaw allows a low-privileged authenticated project user to execute arbitrary commands on the oneuptime-probe server/container by manipulating untrusted Synthetic Monitor code that exposes live Playwright browser objects. Rated 9.9 CRITICAL, the vulnerability has a low attack complexity and requires only low privileges, leading to a complete compromise of confidentiality, integrity, and availability. Currently, there is no evidence of active exploitation, nor are public exploit codes available in Metasploit, Nuclei, or ExploitDB, and it is not listed on CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.0.21CPE matchmatch criteria | cpe:2.3:a:hackerbay:oneuptime:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.