Executive brief
OneUptime is an open-source platform used for monitoring and observability of IT infrastructure. A security flaw in its login system allows an attacker to bypass authentication and log in as any registered user, including administrators. By manipulating the login data sent from a single sign-on (SSO) provider, an attacker can gain unauthorized access to sensitive monitoring data and system configurations.
Technical details
The vulnerability exists in the SAML SSO implementation within `App/FeatureSet/Identity/Utils/SSO.ts`. The root cause is a structural disconnect between how the system verifies cryptographic signatures and how it extracts user identity. Specifically, `isSignatureValid()` uses the `xml-crypto` library to verify the first `<Signature>` element found in the XML DOM, while `getEmail()` uses `xml2js` to always read the identity from the first assertion (`assertion[0]`). An attacker can exploit this by prepending an unsigned, malicious assertion containing a target user's email before a legitimately signed assertion. The system validates the signature on the second assertion but logs the user in based on the first, unsigned assertion. This is exploitable when the Identity Provider (IdP) uses assertion-level signatures rather than response-level signatures. The issue is fixed in version 10.0.42 by ensuring exactly one assertion is present.
Affected products
- OneUptime OneUptime < 10.0.42
Timeline
- 2026-03-31: patched: Version 10.0.42 released
- 2026-03-31: advisory: GitHub Security Advisory GHSA-5w5c-766x-265g published
- 2026-04-02: disclosed: CVE-2026-34840 published to NVD