Skip to content
OneUptime Command Injection Vulnerability Allows Full Server Takeover

OneUptime Command Injection Vulnerability Allows Full Server Takeover

First seen 2 Mar 2026, 14:10 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 16:10 UTC

A critical command injection vulnerability, tracked as CVE-2026-27728, has been identified in OneUptime, affecting versions prior to 10.0.7. This flaw enables authenticated users to execute arbitrary operating system commands on the Probe server, risking complete system compromise for organizations using the affected versions. Immediate patching is advised to mitigate this risk.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 210d ago How this analysis works

Timeline

2026-02-25
CVE-2026-27728 published
2026-03-02
Cyberpress article published
2026-03-02
Gbhackers article published

More articles in this cluster (2)

Following this threat?

Track OneUptime and CVE-2026-27728 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed