External risk intelligence

OneUptime Tenant Isolation Bypass Allows Account Takeover

CVE advisorySeverity: CRITICAL (CVSS 9.9)

CVE-2026-30956

OneUptime is a monitoring and management solution for online services. Such platforms are commonly deployed as internet-facing web applications to provide centralized monitoring, dashboarding, and alerting capabilities for external infrastructure.

Hackerbay Oneuptime

before 10.0.21

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability has been identified in OneUptime, a platform for monitoring and managing online services, affecting versions prior to 10.0.21. This issue could allow a low-privileged user to bypass security controls, leading to unauthorized access to other tenants' data, exposure of sensitive user information, and potentially full account takeover. The main concern is confirming relevance and exposure.

  • Unauthorized access to sensitive customer data.
  • Affects OneUptime, a critical service management tool.
  • Assess OneUptime exposure and potential data impact.

Attack Path

How an attacker could exploit the issue

An attacker with low-level access could exploit this vulnerability by sending specially crafted headers to the OneUptime server. This bypasses security checks, allowing the attacker to access and manipulate data across different tenants, including sensitive user information and password reset tokens, ultimately leading to account takeover.

  • Requires low-privileged access.
  • Triggers by sending forged headers.
  • Risks cross-tenant data exposure and account takeover.

Live Threat

Current exploitation, exposure, and threat context

A low-privileged user could bypass authorization and tenant isolation. This may allow access to project data belonging to other tenants, read sensitive user fields, leak reset password tokens, and reset a victim's password, leading to account takeover when supported by the advisory.

  • Cross-tenant project data exposure.
  • Bypassing authorization with forged headers.
  • Full account takeover possible.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability affects OneUptime deployments, likely managed by platform or application teams responsible for online service monitoring. The immediate priority is to identify all OneUptime instances, assess their exposure and business criticality, locate the accountable owner for each, and then plan remediation based on the identified risk.

  • Platform or application teams own the issue.
  • Verify OneUptime instance exposure and criticality.
  • Plan and execute remediation during maintenance.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is OneUptime?

OneUptime is a software platform designed to monitor and manage the health and performance of online services. It provides teams with centralized dashboards, alerting, and operational oversight for their infrastructure, making it a critical hub for service reliability.

How does CVE-2026-30956 cause an authorization bypass?

This vulnerability is an instance of Improper Authorization (CWE-285) and Missing Authorization (CWE-862). The software incorrectly trusts specific HTTP headers provided by the client, which allows an attacker to disable tenant isolation and skip internal permission checks intended to protect project data.

Does sending standard requests trigger this bug?

No. The vulnerability requires an attacker to specifically manipulate the request by sending a forged 'is-multi-tenant-query' header alongside a controlled 'projectid' header. Standard, legitimate usage of the application that does not involve injecting these specific, malicious headers will not trigger the authorization bypass.

Why should I care about this vulnerability in my environment?

According to Halo Surface Signal, OneUptime is commonly deployed as an internet-facing web application. Because it is often exposed to manage external infrastructure, the ability for a low-privileged user to bypass isolation and take over accounts creates a high risk of cross-tenant data compromise.

Is there a way to secure my OneUptime installation?

Yes. The vulnerability is resolved in version 10.0.21. Your primary step is to identify all running instances of the software and update them to version 10.0.21 or later to ensure the authorization logic correctly validates user access and enforces tenant boundaries.

References