OneUptime is a solution for monitoring and managing online services. In version 9.0.5598, a low-permission user can create new accounts through a direct API request instead of being restricted to the intended interface. This issue has been patched in version 9.1.0.

Project Subscriptions

Vendors Products
Hackerbay Subscribe
Oneuptime Subscribe
Oneuptime Subscribe
Oneuptime Subscribe
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-m449-vh5f-574g OneUptime Unauthorized User Creation via API
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 05 Dec 2025 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Hackerbay
Hackerbay oneuptime
CPEs cpe:2.3:a:hackerbay:oneuptime:9.0.5598:*:*:*:*:*:*:*
Vendors & Products Hackerbay
Hackerbay oneuptime
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'}


Fri, 28 Nov 2025 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Oneuptime
Oneuptime oneuptime
Vendors & Products Oneuptime
Oneuptime oneuptime

Wed, 26 Nov 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 26 Nov 2025 18:30:00 +0000

Type Values Removed Values Added
Description OneUptime is a solution for monitoring and managing online services. In version 9.0.5598, a low-permission user can create new accounts through a direct API request instead of being restricted to the intended interface. This issue has been patched in version 9.1.0.
Title OneUptime Unauthorized User Creation via API
Weaknesses CWE-285
References
Metrics cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-11-26T18:41:53.120Z

Reserved: 2025-11-18T16:14:56.694Z

Link: CVE-2025-65966

cve-icon Vulnrichment

Updated: 2025-11-26T18:41:45.844Z

cve-icon NVD

Status : Analyzed

Published: 2025-11-26T19:15:50.813

Modified: 2025-12-05T14:05:09.610

Link: CVE-2025-65966

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-11-28T08:51:32Z

Weaknesses