Executive brief
OneUptime is an open-source monitoring and incident management platform that uses WebAuthn (hardware security keys and biometric authentication) as a second-factor authentication method. The vulnerability allows attackers who possess a user's password and a captured authentication assertion to bypass 2FA entirely and gain full account access. An attacker can replay a single captured assertion indefinitely, rendering WebAuthn's security protection ineffective.
Technical details
The vulnerability is an authentication bypass in the WebAuthn verification flow. The server generates a challenge during authentication initiation but never stores it server-side (violating the W3C WebAuthn specification). Instead, it accepts the challenge value directly from the client request body during credential verification. Since both the expected challenge and the challenge signed by the authenticator come from the same captured assertion, they always match, allowing an attacker to replay a previously captured valid WebAuthn assertion indefinitely. Exploitation requires the attacker to already possess the victim's password and a valid WebAuthn assertion (obtainable via XSS, network interception, or log exposure). The fix requires storing the challenge server-side (in session or database) and comparing the client-provided challenge against the stored value rather than the client-supplied value. As of the advisory publication, no patched version was available.
Affected products
- OneUptime OneUptime <= 10.0.11
Timeline
- 2026-03-02: disclosed: Advisory published
- 2026-03-02: advisory: GHSA-gjjc-pcwp-c74m and CVE-2026-28787 assigned