CVE-2026-32306Critical· 9.9▾ MidnightOneUptime is a solution for monitoring and managing online services. Prior to 10.0.23, the telemetry aggregation API accepts user-controlled aggregationType, aggregateColumnName, and aggregationTimestampColumnName parameters and interpol…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 54.5 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.9%
OneUptime is a solution for monitoring and managing online services. Prior to 10.0.23, the telemetry aggregation API accepts user-controlled aggregationType, aggregateColumnName, and aggregationTimestampColumnName parameters and interpolates them directly into ClickHouse SQL queries via the .append() method (documented as "trusted SQL"). There is no allowlist, no parameterized query binding, and no input validation. An authenticated user can inject arbitrary SQL into ClickHouse, enabling full database read (including telemetry data from all tenants), data modification, and potential remote code execution via ClickHouse table functions. This vulnerability is fixed in 10.0.23.
oneuptime < 10.0.23Upgrade past the affected range:
oneuptime 10.0.23Connected by shared product, vendor, weakness, or advisory.
CVE-2026-33142High· 8.1OneUptime is a solution for monitoring and managing online services
CVE-2026-33396Critical· 9.9OneUptime is an open-source monitoring and observability platform
CVE-2026-33143High· 7.5OneUptime is a solution for monitoring and managing online services
CVE-2026-32308High· 7.6OneUptime is a solution for monitoring and managing online services
CVE-2026-32598Medium· 6.5OneUptime is a solution for monitoring and managing online services
CVE-2026-30957Critical· 9.9OneUptime is a solution for monitoring and managing online services