OneUptime Command Injection Vulnerability Allows Full Server Takeover

OneUptime Command Injection Vulnerability Allows Full Server Takeover

First seen 2 Mar 2026, 14:10 UTC GbhackersCyberpress 43.2

Article Content

Browse articles
ThreatCluster

A critical command injection vulnerability, tracked as CVE-2026-27728, has been identified in OneUptime, affecting versions prior to 10.0.7. This flaw enables authenticated users to execute arbitrary operating system commands on the Probe server, risking complete system compromise for organizations using the affected versions. Immediate patching is advised to mitigate this risk.

Timeline

2026-02-25
CVE-2026-27728 published
2026-03-02
Cyberpress article published
2026-03-02
Gbhackers article published