LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-30957

CVE-2026-30957 - Vulnerability Analysis

CriticalCVSS: 9.9

Last Updated: March 11, 2026

OneUptime - Remote Code Execution

Published: March 10, 2026Updated: March 11, 2026Remote Exploitable

Overview

OneUptime < 10.0.21 contains a server-side remote code execution caused by execution of untrusted Synthetic Monitor code in Node's vm exposing Playwright browser objects, letting low-privileged authenticated users execute arbitrary commands on the probe server.

Severity & Score

Severity: Critical
CVSS Score: 9.9
EPSS Score: 27.0%(Probability of exploitation in next 30 days)

Impact

Low-privileged authenticated users can execute arbitrary commands on the probe server, leading to full server compromise.

Mitigation

Upgrade to version 10.0.21 or later.

Social Media Activity(2 posts)

TheHackerWire
TheHackerWire
@thehackerwire
Mar 10, 2026

šŸ”“ CVE-2026-30957 - Critical (9.9) OneUptime is a solution for monitoring and managing online services. Prior to 10.0.21, OneUptime Synthetic Monitors allow a low-privileged authenticated project user to execute arbitrary commands on the oneuptime-probe server/container. The root c... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-30957/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post
TheHackerWire
TheHackerWire
@thehackerwire
Mar 10, 2026

šŸ”“ CVE-2026-30957 - Critical (9.9) OneUptime is a solution for monitoring and managing online services. Prior to 10.0.21, OneUptime Synthetic Monitors allow a low-privileged authenticated project user to execute arbitrary commands on the oneuptime-probe server/container. The root c... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-30957/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2026-30957
Severity
Critical
CVSS Score
9.9
Type
remote_code_execution
Status
unconfirmed
EPSS
27.0%
Social Posts
2

CWE

  • CWE-749

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

EPSS Score

27.0%Probability of exploitation in the next 30 days