We found results for “”
CVE-2025-65966
Good to know:
Date: November 26, 2025
OneUptime is a solution for monitoring and managing online services. In version 9.0.5598, a low-permission user can create new accounts through a direct API request instead of being restricted to the intended interface. This issue has been patched in version 9.1.0.
Severity Score
Related Resources (5)
Severity Score
Weakness Type (CWE)
Improper Authorization
CWE-285Top Fix
Upgrade Version
Upgrade to version @oneuptime/common - 9.1.0;https://github.com/OneUptime/oneuptime.git - 9.1.0
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | NONE |
| User Interaction (UI): | NONE |
| Scope (S): | UNCHANGED |
| Confidentiality (C): | NONE |
| Integrity (I): | HIGH |
| Availability (A): | HIGH |
Vulnerabilities
Projects
Contact Us


