Ad

CVE-2026-32598

MEDIUM CVSS 4.0: 6.9 EPSS 0.01%
Updated Mar 13, 2026
Docker
Parameter Value
CVSS 6.9 (MEDIUM)
Fixed In 10.0.24
Type CWE-532
Vendor Docker
Public PoC No

OneUptime is a solution for monitoring and managing online services. Prior to 10.0.24, the password reset flow logs the complete password reset URL — containing the plaintext reset token — at INFO log level, which is enabled by default in production. Anyone with access to application logs (log aggregation, Docker logs, Kubernetes pod logs) can intercept reset tokens and perform account takeover on any user.

This vulnerability is fixed in 10.0.24.

Attack Parameters

Attack Vector
Local
Requires local access
Attack Complexity
Low
Easy to exploit
Attack Requirements
None
No additional conditions
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
None
No data modification
Availability
None
No disruption

CVSS Vector v4.0

Weakness Type (CWE)