Vulnerabilities
Report: CVE-2026-32306 - OneUptime ClickHouse SQL Injection via Aggregate Query Parameters
CVE ID :CVE-2026-32306 Published : March 12, 2026, 9:27 p.m. | 38 minutes ago Description :OneUptime is a solution for monitoring and managing online services. Prior to 10.0.23, the telemetry aggregation API accepts user-controlled aggregationType, aggregateColumnName, and aggregationTimestampColumnName parameters and interpolates them directly into ClickHouse SQL queries via the .append() method (documented as
CVE Details
CVE ID
Published
March 12, 2026