Two high-severity vulnerabilities were disclosed in OneUptime, an open-source monitoring and observability platform, affecting webhook handling and synthetic monitoring. CVE-2026-33143 impacts versions before 10.0.34 and stems from missing verification of the Meta/WhatsApp X-Hub-Signature-256 HMAC signature in the POST /notification/whatsapp/webhook handler. An unauthenticated attacker could forge WhatsApp status update payloads, manipulate notification delivery records, suppress alerts, and corrupt audit trails. The issue was classified as CWE-345 and patched in version 10.0.34.
A second flaw, CVE-2026-33396, affects versions before 10.0.35 and allows a low-privileged authenticated user with the ProjectMember role to achieve remote command execution on the Probe container or host through Synthetic Monitor Playwright script execution. The weakness lies in VMRunner.runCodeInNodeVM, where sandboxed code retained access to a live Playwright page object and could reach dangerous methods such as _browserType.launchServer(...), bypassing an incomplete denylist. The vulnerability was mapped to CWE-78, CWE-693, and CWE-184, carries a CVSS:3.1 AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H rating, and was fixed in OneUptime version 10.0.35.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
CVE-2026-33396 was documented as a vulnerability in OneUptime versions prior to 10.0.35, enabling authenticated low-privilege users to execute arbitrary commands through the Synthetic Monitor Playwright runtime. Public details explained that attackers could reach _browserType.launchServer via page.context().browser() to spawn processes.
OneUptime released version 10.0.35 to address a sandbox escape in the Synthetic Monitor Playwright runtime. The flaw allowed a low-privileged ProjectMember user to achieve remote command execution on the Probe container or host by abusing exposed Playwright objects and incomplete sandbox restrictions.
A high-severity vulnerability, CVE-2026-33143, was publicly disclosed for OneUptime, describing missing signature verification in the /notification/whatsapp/webhook endpoint. The flaw could let unauthenticated attackers forge webhook payloads, suppress alerts, and corrupt audit trails.
OneUptime fixed a vulnerability in the WhatsApp POST webhook handler that failed to verify the Meta/WhatsApp X-Hub-Signature-256 HMAC signature, allowing forged status update payloads to manipulate notification records and audit trails. The issue affected versions prior to 10.0.34.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.