CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2026-32306: oneuptime before 10.0.23 (exclusive), < 10.0.23

CVE-2026-32306. CVSS 3.1 base score 9.9 (CRITICAL, Vendor/CNA). EPSS 0.00911 (percentile 0.58635), scored 2026-10-05.

Affected technology

oneuptime · before 10.0.23 (exclusive)
hackerbay

oneuptime · < 10.0.23
OneUptime

Component: Not specified by the source

Attack conditions (Vendor/CNA, CVSS 3.1): Network (remote) · Low privileges required · No user interaction required

What an attacker can do

An authenticated user can inject arbitrary SQL into ClickHouse, enabling full database read (including telemetry data from all tenants), data modification, and potential remote code execution via ClickHouse table functions. Vendor/CNA’s CVSS 3.1 assessment (base score 9.9/10) rates confidentiality, integrity and availability impact as high.

Published

CWE
CWE-89
CCR priority
39.8 /100 (P4)
CVSS 3.1
9.9 /10 · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H · Vendor/CNA
EPSS
0.00911 · percentile 0.58698 · 2026-10-06
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-32306.html