External risk intelligence

OneUptime SQL Injection Vulnerability Allows Database Read Modify and RCE

CVE advisorySeverity: CRITICAL (CVSS 9.9)

CVE-2026-32306

OneUptime is a solution for monitoring online services, which is typically deployed as an internet-facing web application or service dashboard to monitor external endpoints, making its API endpoints commonly accessible or internet-facing in many standard deployment environments.

SQL Injection

Hackerbay Oneuptime

before 10.0.23

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a critical vulnerability in OneUptime, a service monitoring solution. The issue allows authenticated users to execute arbitrary commands within the underlying database, potentially leading to data breaches or system compromise. The primary concern is to determine if your OneUptime instances are affected and to confirm exposure.

  • SQL injection allows database access and control.
  • Affects critical online service monitoring tools.
  • Confirm relevance and exposure; assess potential impact.

Attack Path

How an attacker could exploit the issue

An attacker with authenticated access can leverage this vulnerability by sending specially crafted requests to the telemetry aggregation API. By manipulating parameters within these requests, the attacker can inject arbitrary SQL commands into the underlying ClickHouse database. This allows them to read sensitive telemetry data from all users, alter existing data, and potentially execute commands on the server.

  • Authenticated user required.
  • Inject SQL via API parameters.
  • Database compromise and RCE risk.

Live Threat

Current exploitation, exposure, and threat context

An authenticated user could inject malicious SQL into the ClickHouse database, potentially exposing telemetry data from all tenants. This could also lead to data modification or remote code execution.

  • Telemetry data from all tenants.
  • SQL injection via API parameters.
  • Unauthorized data access and modification.

Operational Fix

Recommended remediation, mitigation, and detection steps

Determine which teams manage OneUptime instances and their ClickHouse databases to assess exposure and plan remediation. The first practical step involves identifying all OneUptime deployments, confirming their accessibility and business criticality, locating the accountable owners, and then prioritizing response based on risk.

  • Application and database teams own the issue.
  • Verify OneUptime deployment reachability.
  • Plan risk-based remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is OneUptime?

OneUptime is a monitoring solution used by organizations to track the health, performance, and uptime of online services and infrastructure. It provides centralized dashboards to manage service alerts and collect telemetry data, helping teams maintain reliable web applications.

What does CWE-89 mean for CVE-2026-32306?

This vulnerability is classified as CWE-89, or Improper Neutralization of Special Elements used in an SQL Command. In plain terms, the software fails to sanitize input, allowing an attacker to inject their own database commands. In this CVE, the telemetry API takes user-provided parameters and inserts them directly into ClickHouse queries without verification.

How is this SQL injection triggered?

An authenticated user triggers the bug by sending specifically crafted requests to the telemetry aggregation API. By manipulating parameters such as the aggregation type or column names, the attacker can force the system to execute unauthorized SQL queries. Note that this cannot be triggered by unauthenticated users; valid application credentials are a mandatory requirement.

Do I need to worry if my instance is internal?

While the vulnerability requires authentication, you should still evaluate your risk. Halo Surface Signal identifies OneUptime as a solution typically deployed as an internet-facing dashboard. If your instance is exposed to the internet, the attack surface is broader, increasing the likelihood that a compromised account could lead to a full database breach or server-level compromise.

When should I update OneUptime?

You should prioritize updating to version 10.0.23 or later immediately. Since this flaw allows for unauthorized data access and potential remote code execution, identifying all running instances and applying the vendor-supplied fix is the most effective way to eliminate the risk of database manipulation.

References