High severity8.2NVD Advisory· Published Nov 26, 2025· Updated Jun 17, 2026
CVE-2025-66028
CVE-2025-66028
Description
OneUptime is a solution for monitoring and managing online services. Prior to version 8.0.5567, OneUptime is vulnerable to privilege escalation via Login Response Manipulation. During the login process, the server response included a parameter called isMasterAdmin. By intercepting and modifying this parameter value from false to true, it is possible to gain access to the admin dashboard interface. However, an attacker may be unable to view or interact with the data if they still do not have sufficient permissions. This issue has been patched in version 8.0.5567.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
@oneuptime/commonnpm | < 8.0.5567 | 8.0.5567 |
Affected products
3Patches
Vulnerability mechanics
References
4- github.com/OneUptime/oneuptime/commit/3e72b2a9a4f50f98cf1f6cf13fa3e405715bb370nvdPatchWEB
- github.com/OneUptime/oneuptime/security/advisories/GHSA-675q-66gf-gqg8nvdExploitVendor AdvisoryWEB
- github.com/advisories/GHSA-675q-66gf-gqg8ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-66028ghsaADVISORY
News mentions
0No linked articles in our index yet.