


Perceptive Security
SOC/SIEM Consultancy

OneUptime is a solution for monitoring and managing online services. Prior to 10.0.20, OneUptime Synthetic Monitors allow low-privileged project users to submit…
Published:
9 March 2026 at 23:00:00
Alert date:
10 March 2026 at 18:06:15
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications
OneUptime monitoring solution contains a critical remote code execution vulnerability in versions prior to 10.0.20. Low-privileged users can submit custom Playwright code that executes on the oneuptime-probe service. The vulnerability allows attackers to bypass sandbox restrictions by directly accessing Playwright browser objects to spawn arbitrary executables on the host container. This creates a server-side RCE primitive without requiring traditional sandbox escape techniques. The issue is resolved in version 10.0.20.
Technical details
Mitigation steps:
Affected products:
OneUptime
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-30921
https://github.com/OneUptime/oneuptime/security/advisories/GHSA-4j36-39gm-8vq8
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
