← Back to CVEs
CVE-2026-35053
N/ADescription
OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, the Worker service's ManualAPI exposes workflow execution endpoints (GET /workflow/manual/run/:workflowId and POST /workflow/manual/run/:workflowId) without any authentication middleware. An attacker who can obtain or guess a workflow ID can trigger arbitrary workflow execution with attacker-controlled input data, enabling JavaScript code execution, notification abuse, and data manipulation. This issue has been patched in version 10.0.42.
CVE Details
CVSS v3.1 ScoreN/A
Published4/2/2026
Last Modified4/3/2026
Sourcenvd
Honeypot Sightings0
Weaknesses (CWE)
CWE-306
References
https://github.com/OneUptime/oneuptime/releases/tag/10.0.42(security-advisories@github.com)
https://github.com/OneUptime/oneuptime/security/advisories/GHSA-6c3w-7xg4-4cf7(security-advisories@github.com)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.