Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-m449-vh5f-574g | OneUptime Unauthorized User Creation via API |
Fri, 05 Dec 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hackerbay
Hackerbay oneuptime |
|
| CPEs | cpe:2.3:a:hackerbay:oneuptime:9.0.5598:*:*:*:*:*:*:* | |
| Vendors & Products |
Hackerbay
Hackerbay oneuptime |
|
| Metrics |
cvssV3_1
|
Fri, 28 Nov 2025 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Oneuptime
Oneuptime oneuptime |
|
| Vendors & Products |
Oneuptime
Oneuptime oneuptime |
Wed, 26 Nov 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 26 Nov 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OneUptime is a solution for monitoring and managing online services. In version 9.0.5598, a low-permission user can create new accounts through a direct API request instead of being restricted to the intended interface. This issue has been patched in version 9.1.0. | |
| Title | OneUptime Unauthorized User Creation via API | |
| Weaknesses | CWE-285 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-11-26T18:41:53.120Z
Reserved: 2025-11-18T16:14:56.694Z
Link: CVE-2025-65966
Updated: 2025-11-26T18:41:45.844Z
Status : Analyzed
Published: 2025-11-26T19:15:50.813
Modified: 2025-12-05T14:05:09.610
Link: CVE-2025-65966
No data.
OpenCVE Enrichment
Updated: 2025-11-28T08:51:32Z
Github GHSA