External risk intelligence

OneUptime Synthetic Monitoring Remote Code Execution

CVE advisorySeverity: CRITICAL (CVSS 9.9)

CVE-2026-33396

OneUptime is a monitoring and observability platform typically deployed as a web-based service or portal accessible to users for managing infrastructure. Because it is designed to provide dashboards and synthetic monitoring capabilities, it is commonly deployed as an internet-facing web application, making the interface reachable to authenticated users over the network.

OS Command Injection

Hackerbay Oneuptime

before 10.0.35

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a critical vulnerability within the OneUptime monitoring platform, specifically allowing authenticated users with limited privileges to execute arbitrary commands on the system. This could potentially lead to unauthorized access and control over the affected infrastructure.

  • Allows limited users to run any command.
  • Affects systems managing critical infrastructure.
  • Confirm relevance; critical systems warrant attention.

Attack Path

How an attacker could exploit the issue

An attacker with project member privileges can execute arbitrary commands on the server by creating a specially crafted synthetic monitor. This monitor leverages an incomplete sandbox that fails to block access to critical Playwright objects, allowing the attacker to bypass restrictions and launch processes on the Probe container.

  • Requires authenticated access.
  • Abuse Playwright script execution.
  • Remote command execution risk.

Live Threat

Current exploitation, exposure, and threat context

A low-privileged authenticated user could execute arbitrary commands on the Probe container or host. This is possible by exploiting an incomplete sandbox when running synthetic monitor scripts, allowing the user to bypass restrictions and launch unintended processes.

  • System access and arbitrary code execution.
  • Abuse of synthetic monitor script execution.
  • Compromised monitoring infrastructure.

Operational Fix

Recommended remediation, mitigation, and detection steps

The OneUptime platform, used for monitoring and observability, is likely managed by platform or application teams. The first practical step is to identify all OneUptime deployments, assess their reachability and business criticality, and confirm the accountable owner. Subsequently, a remediation plan should be developed based on the identified risks.

  • Platform or application teams own this.
  • Verify OneUptime deployment reachability.
  • Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is OneUptime?

OneUptime is an open-source platform used by organizations to monitor the health and performance of their infrastructure and services. It provides tools for observability and synthetic monitoring, which involves running automated scripts to simulate user interactions and ensure web services remain functional and responsive.

How does CVE-2026-33396 work?

This vulnerability involves an incomplete security sandbox used when executing synthetic monitor scripts. The system uses a denylist to prevent scripts from accessing dangerous functions, but it fails to block certain Playwright properties. An attacker can use this oversight to bypass the sandbox and execute unauthorized commands on the underlying host or container, a weakness categorized as Improper Neutralization of Special Elements (CWE-78, CWE-184, and CWE-693).

What triggers the command execution in this CVE?

The issue is triggered when an authenticated user with low-level permissions creates a malicious synthetic monitor script. The vulnerability does not arise from standard monitoring tasks; it requires specific, crafted code that intentionally traverses the permitted objects to reach forbidden functions like process launching. If the script does not attempt to access these specific unblocked Playwright properties, the underlying host remains secure.

Is my OneUptime instance at risk?

Halo Surface Signal indicates that OneUptime is often deployed as an internet-facing web portal to provide accessible dashboards and monitoring capabilities to team members. Because this vulnerability can be exploited by any authenticated project member, instances that are reachable over the network and allow users to create synthetic monitors are at higher risk of unauthorized command execution.

How do I secure my environment against this?

The primary step is to identify all versions of OneUptime running in your environment. If you are on a version earlier than 10.0.35, you should plan to update immediately, as version 10.0.35 contains the necessary patch to close the sandbox gaps. Consult your infrastructure team to assess the reachability of your deployments and ensure that only trusted users have the project permissions required to create synthetic monitors.

References