id: CVE-2026-32230 info: name: Uptime-Kuma < v1.23.0 - Improper Access Control author: ritikchaddha severity: medium description: | Uptime-Kuma before v1.23.0 is vulnerable to an information disclosure issue due to missing authorization on the /api/badge/1/ping/24 endpoint. An unauthenticated attacker can access this endpoint to leak ping statistics, such as average ping and ping history, for existing monitors without needing access to the protected status page. This can lead to unintended exposure of internal monitoring data. impact: | Information disclosure of monitor ping data to unauthenticated attackers, potentially aiding reconnaissance efforts. remediation: | Upgrade to Uptime-Kuma version 1.23.0 or later, which patches the vulnerable endpoint by introducing proper authorization checks. reference: - https://github.com/advisories/GHSA-c7hf-c5p5-5g6h - https://nvd.nist.gov/vuln/detail/CVE-2026-32230 classification: cve-id: CVE-2026-32230 epss-score: 0.00905 epss-percentile: 0.56078 cwe-id: CWE-862 cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N cvss-score: 5.3 cpe: cpe:2.3:a:louislam:uptime-kuma:*:*:*:*:*:*:*:* metadata: verified: true max-request: 1 vendor: louislam product: uptime-kuma shodan-query: title:"uptime-kuma" tags: cve,cve2026,uptime-kuma,exposure http: - method: GET path: - "{{BaseURL}}/api/badge/1/ping/24" matchers: - type: dsl dsl: - "status_code == 200" - "contains(body, 'Avg. Ping (')" condition: and # digest: 4b0a00483046022100a802e1cd1008523bc39d7abe2e98520a796e1a593e1b7b9efc4b99eaf0b53e63022100d68bf158925ed43b40a77ce2db8ced88f3d1e1efa7cc8264edeef1e32c711545:922c64590222798bb761d5b6d8e72950