Description
During the login process, the server response included a parameter called isMasterAdmin. By intercepting and modifying this parameter value from false to true, a user is able to gain access to the admin dashboard interface.
Recommendation
Update the @oneuptime/common package to the latest compatible version. Followings are version details:
- Affected version(s): < 8.0.5567
- Patched version(s): 8.0.5567
References
Could your website be exposed too?
SmartScanner can check your website for OneUptime is Vulnerable to Privilege Escalation via Login Response Manipulation and gives you actionable findings to investigate.
Start a free scanRelated Issues
- OneUptime Vulnerable to a Privilege Escalation via Local Storage Key Manipulation - CVE-2024-29194
- OneUptime Unauthorized User Creation via API - CVE-2025-65966
- Cube Core is vulnerable to privilege escalation via a specially crafted request - CVE-2026-25958
- FUXA Vulnerable to Pre-auth RCE via Path Manipulation & Configuration Injection - CVE-2026-43945


