CVE Explorer
CVE-2026-30956
OneUptime is a solution for monitoring and managing online services. Prior to 10.0.21, a low‑privileged user can bypass authorization and tenant isolation in OneUptime v10.0.20 and earlier by sending a forged is-multi-tenant-query header together with a controlled projectid header. Because the server trusts this client-supplied header, internal permission checks in BasePermission are skipped and tenant scoping is disabled. This allows attackers to access project data belonging to other tenants,
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"cweId":"CWE-285","description":"CWE-285: Improper Authorization","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:7e31e6c3000133c3b9b3d1a99b9dcbbc81c240eea876117a32fa052b71dad10f · sha256:df4eb3c572fcfccd… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-862","description":"CWE-862: Missing Authorization","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:7e31e6c3000133c3b9b3d1a99b9dcbbc81c240eea876117a32fa052b71dad10f · sha256:df4eb3c572fcfccd… · /containers/cna/problemTypes/1/descriptions/0
Affected products and versions
1 source assertion{"product":"oneuptime","vendor":"OneUptime","versions":[{"status":"affected","version":"< 10.0.21"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:7e31e6c3000133c3b9b3d1a99b9dcbbc81c240eea876117a32fa052b71dad10f · sha256:df4eb3c572fcfccd… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":10,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:7e31e6c3000133c3b9b3d1a99b9dcbbc81c240eea876117a32fa052b71dad10f · sha256:df4eb3c572fcfccd… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
2 source assertions{"cweId":"CWE-285","description":"CWE-285: Improper Authorization","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:7e31e6c3000133c3b9b3d1a99b9dcbbc81c240eea876117a32fa052b71dad10f · sha256:df4eb3c572fcfccd… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-862","description":"CWE-862: Missing Authorization","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:7e31e6c3000133c3b9b3d1a99b9dcbbc81c240eea876117a32fa052b71dad10f · sha256:df4eb3c572fcfccd… · /containers/cna/problemTypes/1/descriptions/0
Source references
2 source assertions{"name":"https://github.com/OneUptime/oneuptime/releases/tag/10.0.21","tags":["x_refsource_MISC"],"url":"https://github.com/OneUptime/oneuptime/releases/tag/10.0.21"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:7e31e6c3000133c3b9b3d1a99b9dcbbc81c240eea876117a32fa052b71dad10f · sha256:df4eb3c572fcfccd… · /containers/cna/references/1
{"name":"https://github.com/OneUptime/oneuptime/security/advisories/GHSA-r5v6-2599-9g3m","tags":["x_refsource_CONFIRM"],"url":"https://github.com/OneUptime/oneuptime/security/advisories/GHSA-r5v6-2599-9g3m"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:7e31e6c3000133c3b9b3d1a99b9dcbbc81c240eea876117a32fa052b71dad10f · sha256:df4eb3c572fcfccd… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.