OneUptime is Vulnerable to Privilege Escalation via Login Response Manipulation
- Severity:
- Medium
Description
During the login process, the server response included a parameter called isMasterAdmin. By intercepting and modifying this parameter value from false to true, a user is able to gain access to the admin dashboard interface.
Recommendation
Update the @oneuptime/common package to the latest compatible version. Followings are version details:
- Affected version(s): < 8.0.5567
- Patched version(s): 8.0.5567
References
Related Issues
- OneUptime Vulnerable to a Privilege Escalation via Local Storage Key Manipulation - CVE-2024-29194
- OneUptime Unauthorized User Creation via API - CVE-2025-65966
- Cube Core is vulnerable to privilege escalation via a specially crafted request - CVE-2026-25958
- FUXA Vulnerable to Pre-auth RCE via Path Manipulation & Configuration Injection - CVE-2026-43945
You might also like:
- Tags:
- npm
- @oneuptime/common
Anything's wrong? Let us know Last updated on November 27, 2025


