Executive brief
OneUptime is an open-source monitoring and incident management platform. A low-privileged user can bypass authorization controls and tenant isolation by forging an HTTP header, allowing them to access other users' projects, read sensitive account data including password reset tokens, and fully take over victim accounts without any additional exploitation steps.
Technical details
The vulnerability is an authorization bypass and tenant isolation failure in OneUptime v10.0.20 and earlier. The API server trusts a client-controlled HTTP header (is-multi-tenant-query) to determine whether permission checks should be skipped. When this header is present, all permission validation layers in BasePermission are bypassed, including table-level, query-level, and select-level checks. An authenticated attacker can send this forged header to access cross-tenant data, including sensitive fields like plaintext password reset tokens stored in the User model. Combined with the password reset endpoint, this enables full account takeover. The vulnerability requires authentication but affects all multi-tenant isolation mechanisms. Patched in version 10.0.21.
Affected products
- OneUptime OneUptime < 10.0.21
Timeline
- 2026-03-10: disclosed
- 2026-03-08: patched: Version 10.0.21 released