CVE-2026-33142 | oneuptime up to 10.0.33 API Request _aggregateBy sql injection (GHSA-gcg3-c5p2-cqgg)
A vulnerability has been found in oneuptime up to 10.0.33 and classified as critical. Affected is the function _aggregateBy of the component API Request Handler. Performing a manipulation results in sql injection.
This vulnerability is identified as CVE-2026-33142. The attack can be initiated remotely. There is not any exploit available.
The affected component should be upgraded.