CVE-2026-32306 is a critical SQL injection vulnerability in OneUptime versions prior to 10.0.23. An authenticated user can exploit this flaw in the telemetry aggregation API by injecting arbitrary SQL into ClickHouse queries due to direct interpolation of user-controlled parameters without validation. This allows for full database read (including all tenant data), data modification, and potential remote code execution, resulting in a CVSS score of 9.9 Critical. There is currently no public exploit code available, and the vulnerability is not known to be actively exploited, with minimal community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.0.23CPE matchmatch criteria | cpe:2.3:a:hackerbay:oneuptime:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.