OneUptime Unauthorized User Creation via API
Description
Published by the National Vulnerability Database
Nov 26, 2025
Published to the GitHub Advisory Database
Nov 26, 2025
Reviewed
Nov 26, 2025
Last updated
Dec 1, 2025
Summary
A low-permission user can create new accounts through a direct API request instead of being restricted to the intended interface.
PoC
A low-permission user sends a crafted API request to the user-creation endpoint and the system creates the account successfully.

Impact
This allows attackers to create unauthorized accounts.
References