PT-2025-48171 · Oneuptime · Oneuptime

Published

2025-11-26

·

Updated

2025-12-05

·

CVE-2025-65966

CVSS v4.0

8.8

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OneUptime versions prior to 9.1.0
Description OneUptime, a service monitoring solution, allows a low-permission user to create new accounts by directly accessing an API, bypassing the intended user interface restrictions. The vulnerable API endpoint allows unauthorized account creation. The affected version is 9.0.5598.
Recommendations Update to version 9.1.0 or later.

Exploit

Fix

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-65966
GHSA-M449-VH5F-574G

Affected Products

Oneuptime