CVE-2026-33396 is a critical remote command execution vulnerability affecting OneUptime, an open-source monitoring and observability platform, in versions prior to 10.0.35. A low-privileged authenticated user (ProjectMember) can exploit an incomplete sandbox denylist within the Synthetic Monitor Playwright script execution to spawn arbitrary processes on the Probe container or host. This vulnerability carries a CVSS score of 9.9 Critical, indicating a network-exploitable flaw with low attack complexity and high impact on confidentiality, integrity, and availability. While there are no known public exploits or evidence of active exploitation, the vulnerability has garnered some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.0.35CPE matchmatch criteria | cpe:2.3:a:hackerbay:oneuptime:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.