Cyberpress
OneUptime Command Injection Vulnerability Allows Full Server Takeover
First seen 2 Mar 2026, 14:10 UTC
•
•43.2
Export
Article Content
Browse articles
A critical command injection vulnerability, tracked as CVE-2026-27728, has been identified in OneUptime, affecting versions prior to 10.0.7. This flaw enables authenticated users to execute arbitrary operating system commands on the Probe server, risking complete system compromise for organizations using the affected versions. Immediate patching is advised to mitigate this risk.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Timeline
2026-02-25
CVE-2026-27728 published
2026-03-02
Cyberpress article published
2026-03-02
Gbhackers article published