CVE-2026-35053 is a critical unauthenticated workflow execution vulnerability in OneUptime, an open-source monitoring and observability platform, affecting versions prior to 10.0.42. This flaw allows an unauthenticated attacker, by obtaining or guessing a workflow ID, to trigger arbitrary workflow execution with controlled input. This can lead to severe consequences including JavaScript code execution, notification abuse, and data manipulation, earning a CVSS score of 9.2 Critical. Although there is no public exploit code or evidence of active exploitation, the vulnerability is listed on a "Hot List" and has seen minimal community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.0.42CPE matchmatch criteria | cpe:2.3:a:hackerbay:oneuptime:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.