CVE-2026-33396Critical· 9.9▾ MidnightOneUptime is an open-source monitoring and observability platform. Prior to version 10.0.35, a low-privileged authenticated user (ProjectMember) can achieve remote command execution on the Probe container/host by abusing Synthetic Monito…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 54.5 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
1.1%
OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.35, a low-privileged authenticated user (ProjectMember) can achieve remote command execution on the Probe container/host by abusing Synthetic Monitor Playwright script execution. Synthetic monitor code is executed in VMRunner.runCodeInNodeVM with a live Playwright page object in context. The sandbox relies on a denylist of blocked properties/methods, but it is incomplete. Specifically, _browserType and launchServer are not blocked, so attacker code can traverse page.context().browser()._browserType.launchServer(...) and spawn arbitrary processes. Version 10.0.35 contains a patch.
oneuptime < 10.0.35Upgrade past the affected range:
oneuptime 10.0.35Connected by shared product, vendor, weakness, or advisory.
CVE-2026-33142High· 8.1OneUptime is a solution for monitoring and managing online services
CVE-2026-33143High· 7.5OneUptime is a solution for monitoring and managing online services
CVE-2026-32308High· 7.6OneUptime is a solution for monitoring and managing online services
CVE-2026-32598Medium· 6.5OneUptime is a solution for monitoring and managing online services
CVE-2026-32306Critical· 9.9OneUptime is a solution for monitoring and managing online services
CVE-2026-30957Critical· 9.9OneUptime is a solution for monitoring and managing online services