External risk intelligence

OneUptime Synthetic Monitors Remote Code Execution Vulnerability.

CVE advisorySeverity: CRITICAL (CVSS 9.9)

CVE-2026-30957

OneUptime monitoring probes can be deployed within internal infrastructure or behind controlled network perimeters. While the application manages online services, the specific synthetic monitoring probe component is not always a public-facing edge service in all deployment architectures, making internet reachability possible but not guaranteed for this specific sub-component.

Remote Code Execution

Hackerbay Oneuptime

before 10.0.21

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a critical vulnerability in OneUptime, a service monitoring solution. A flaw allows authenticated users to execute unauthorized commands on the monitoring probe servers, potentially leading to system compromise. The main concern is confirming relevance and exposure within your OneUptime deployments.

  • Low-privilege users can run unauthorized commands.
  • Monitoring probes can be compromised via this flaw.
  • Confirm OneUptime deployment relevance and exposure.

Attack Path

How an attacker could exploit the issue

An attacker with project user access can leverage OneUptime's synthetic monitoring feature to run malicious code on the probe server. This occurs when the untrusted code interacts with live browser objects, allowing the attacker to manipulate them and execute arbitrary commands. This vulnerability enables server-side remote code execution.

  • Requires authenticated project user access.
  • Triggered by executing untrusted synthetic monitor code.
  • Results in server-side remote code execution.

Live Threat

Current exploitation, exposure, and threat context

A low-privileged authenticated user could execute arbitrary commands on the OneUptime probe server, potentially impacting the integrity and availability of the monitoring service and any systems it oversees. This occurs when untrusted code within Synthetic Monitors is executed with access to live browser objects, allowing the probe to spawn attacker-controlled executables.

  • Probe server and its command execution.
  • Malicious monitor code exploiting browser objects.
  • Compromised monitoring and service availability.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability affects OneUptime Synthetic Monitors, a component of OneUptime used for monitoring and managing online services. The primary risk lies with application owners or platform teams responsible for the OneUptime deployment and its synthetic probes. The first practical step is to identify all OneUptime probe instances, determine their reachability, assess their business criticality, and confirm the accountable owner for each instance before planning remediation efforts.

  • Application and platform teams own the issue.
  • Verify probe reachability and criticality first.
  • Plan remediation based on risk and ownership.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is OneUptime and how does it function?

OneUptime is an observability platform designed to monitor and manage the health of online services. It utilizes synthetic monitors, which are automated scripts that simulate user interactions to verify site performance. These monitors run on specialized probe servers or containers that execute code to interact with web pages, ensuring that digital services remain available and responsive for end users.

What is the vulnerability in CVE-2026-30957?

This vulnerability is classified as CWE-749, or Exposed Dangerous Method. It occurs because the synthetic monitoring system inadvertently provides untrusted scripts access to live browser objects. A user can leverage this unintended permission to bypass isolation and execute arbitrary commands directly on the underlying probe server, resulting in a critical remote code execution flaw.

How can an attacker trigger this vulnerability?

An attacker needs authenticated project user access to the OneUptime platform to create or modify a synthetic monitor. By injecting malicious code into the monitor, they can call Playwright APIs on the exposed browser objects to spawn unauthorized executables. It is important to note that this does not require a complex virtual machine sandbox escape; the flaw exists within the direct interaction between the script and the probe's browser environment.

Is my OneUptime instance at risk?

Risk depends on your specific deployment architecture. According to Halo Surface Signal, OneUptime probes are not always internet-facing; they are often deployed within internal networks or behind controlled perimeters. While internet reachability is possible, you should assess whether your specific probe instances are accessible from outside your environment, as this increases the likelihood of a successful attack by an authenticated user.

What should I do if I am running OneUptime?

Your first step is to identify all deployed OneUptime probe instances and confirm who is responsible for their maintenance. Once you have an inventory, assess the business criticality of those probes and check their network reachability. Finally, prioritize updating your OneUptime environment to version 10.0.21 or later, which contains the fix for this security flaw.

References