CVE 6.9 MEDIUM

OneUptime is Vulnerable to Privilege Escalation via Login Response Manipulation_CVE-2025-66028

6.9 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

Description

OneUptime is a solution for monitoring and managing online services. Prior to version 8.0.5567, OneUptime is vulnerable to privilege escalation via Login Response Manipulation. During the login process, the server response included a parameter called isMasterAdmin. By intercepting and modifying this parameter value from false to true, it is possible to gain access to the admin dashboard interface. However, an attacker may be unable to view or interact with the data if they still do not have sufficient permissions. This issue has been patched in version 8.0.5567.

Basic Information

ID CVE-2025-66028
Source GitHub_M
Published Nov 26, 2025 at 18:11
Modified Nov 26, 2025 at 18:37

Affected Product

Vendor OneUptime
Product oneuptime
Version < 8.0.5567
Affected Versions OneUptime oneuptime < 8.0.5567

CWE Classification

References

πŸ’­ Join the Security Discussion

πŸ”’ Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.