CVE-2026-28787

8.2

OneUptime · OneUptime

OneUptime versions 10.0.11 and prior contain a critical authentication bypass vulnerability due to improper WebAuthn challenge handling, allowing for replay attacks.

Executive summary

A vulnerability in the OneUptime WebAuthn implementation allows attackers to bypass second-factor authentication via replay attacks, posing a severe risk to account security.

Vulnerability

The application fails to store WebAuthn challenges server-side, instead returning them to the client and accepting them back during verification. This flaw allows an authenticated attacker to replay captured WebAuthn assertions indefinitely, effectively bypassing multi-factor authentication requirements.

Business impact

This vulnerability carries a CVSS score of 8.2, representing a high risk to organizational security. Successful exploitation allows unauthorized parties to bypass critical second-factor authentication controls, potentially leading to full account takeover, unauthorized access to sensitive service management data, and significant reputational damage.

Remediation

Immediate Action: As no patch is currently available, administrators should prioritize implementing alternative authentication controls or restricting access to the affected management interfaces until a fix is released.

Proactive Monitoring: Review authentication logs for anomalous or repetitive WebAuthn login attempts and monitor for unusual traffic patterns originating from user sessions.

Compensating Controls: Deploy a Web Application Firewall (WAF) to restrict unauthorized access to authentication endpoints and consider enforcing additional IP-based access controls to limit the surface area for potential replay attacks.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the lack of a vendor-provided patch and the presence of a known proof-of-concept, this vulnerability must be treated with high urgency. Organizations utilizing OneUptime should immediately evaluate their risk exposure and implement compensating controls, such as limiting network access to the monitoring interface, while awaiting an official security update.

More OneUptime CVEs

Sources