OneUptime A.I CyberSecurity Scoring
OneUptime
Company Information
Website:https://oneuptime.com
Employees number:2
Number of followers:0
NAICS:5112
Industry Type:Software Development
Homepage:oneuptime.com
OneUptime Risk Score (AI oriented)
Between 750 and 799
OneUptimeSoftware Development
Updated:
04/04/2026
04/04/2026
786/1000
Fair
Baa
OneUptime Global Score (TPRM)
xxxx
OneUptimeSoftware Development
Score locked

OneUptimeFair
Current Score
786Baa (FAIR)
01000
1 incidents
-1 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
786
MAY 2026
786
APRIL 2026
786
MARCH 2026
787
Vulnerability
02 Mar 2026 • OneUptime
OneUptime: OneUptime Command Injection Vulnerability Poses Major Risk of Full System Takeover
Critical Command Injection Flaw in OneUptime Exposes Systems to Remote Takeover
786
CRITICAL-1
ONE1772454233
Critical Command Injection Flaw in OneUptime Exposes Systems to Remote Takeover
A severe command injection vulnerability, tracked as CVE-2026-27728, has been discovered in OneUptime, a platform used for monitoring and managing online services. The flaw allows authenticated users to execute arbitrary operating system commands on the Probe server, risking full system compromise.
The vulnerability resides in the NetworkPathMonitor.performTraceroute() function within OneUptime’s Probe Server component. The function processes user-controlled input specifically the destination field in monitor configurations using Node.js’s exec() function, which spawns shell commands. Due to improper input sanitization, attackers can inject malicious commands via shell metacharacters (e.g., `;`, `|`, `&`, `$()`, or backticks), bypassing intended traceroute operations.
Exploitation requires only low-level authentication as a project user. By crafting a malicious monitor configuration (e.g., `example.com; cat /etc/passwd`), an attacker can execute arbitrary commands with the same privileges as the Probe server process. Successful exploitation could lead to data exfiltration, lateral movement, or complete server takeover.
OneUptime addressed the issue in version 10.0.7, replacing the vulnerable exec() function with execFile(), which executes commands directly without shell interpretation, mitigating the injection risk. Organizations using versions prior to 10.0.7 are advised to patch immediately. Additional mitigation steps include auditing monitor configurations for suspicious inputs, monitoring for unusual system activity, and restricting Probe server access if patching is delayed.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2026
787
JANUARY 2026
787
DECEMBER 2025
787
NOVEMBER 2025
787
OCTOBER 2025
787
SEPTEMBER 2025
787
AUGUST 2025
787
JULY 2025
787
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for OneUptime ??
What was OneUptime's A.I Rankiteo Cyber Score in May 2026 ??
What was OneUptime's A.I Rankiteo Cyber Score in April 2026 ??
What was OneUptime's A.I Rankiteo Cyber Score in March 2026 ??
What was OneUptime's A.I Rankiteo Cyber Score in February 2026 ??
What was OneUptime's A.I Rankiteo Cyber Score in January 2026 ??
What was OneUptime's A.I Rankiteo Cyber Score in December 2025 ??
What was OneUptime's A.I Rankiteo Cyber Score in November 2025 ??
What was OneUptime's A.I Rankiteo Cyber Score in October 2025 ??
What was OneUptime's A.I Rankiteo Cyber Score in September 2025 ??
What was OneUptime's A.I Rankiteo Cyber Score in August 2025 ??
What was OneUptime's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on OneUptime's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with OneUptime ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view OneUptime's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?