TROYANOSYVIRUS
Zuruck zu CVEs

CVE-2026-35053

N/A

Beschreibung

OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, the Worker service's ManualAPI exposes workflow execution endpoints (GET /workflow/manual/run/:workflowId and POST /workflow/manual/run/:workflowId) without any authentication middleware. An attacker who can obtain or guess a workflow ID can trigger arbitrary workflow execution with attacker-controlled input data, enabling JavaScript code execution, notification abuse, and data manipulation. This issue has been patched in version 10.0.42.

CVE Details

CVSS v3.1 BewertungN/A
Veroffentlicht4/2/2026
Zuletzt geandert4/3/2026
Quellenvd
Honeypot-Sichtungen0

Schwachen (CWE)

CWE-306

IOC Korrelationen

Keine Korrelationen erfasst

This product uses data from the NVD API but is not endorsed or certified by the NVD.