CVE-2025-66028

HIGH

OneUptime <8.0.5567 - Privilege Escalation

Title source: llm
STIX 2.1

Description

OneUptime is a solution for monitoring and managing online services. Prior to version 8.0.5567, OneUptime is vulnerable to privilege escalation via Login Response Manipulation. During the login process, the server response included a parameter called isMasterAdmin. By intercepting and modifying this parameter value from false to true, it is possible to gain access to the admin dashboard interface. However, an attacker may be unable to view or interact with the data if they still do not have sufficient permissions. This issue has been patched in version 8.0.5567.

Scores

CVSS v3 8.2
EPSS 0.0026
EPSS Percentile 17.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-284
Status published
Products (2)
hackerbay/oneuptime < 8.0.5567
oneuptime/common 0 - 8.0.5567npm
Published Nov 26, 2025
Tracked Since Feb 18, 2026