CVE-2026-34840 | oneuptime up to 10.0.41 SSO.ts isSignatureValid signature verification (GHSA-5w5c-766x-265g)
A vulnerability classified as critical has been found in oneuptime up to 10.0.41. This affects the function isSignatureValid of the file App/FeatureSet/Identity/Utils/SSO.ts. Performing a manipulation results in improper verification of cryptographic signature.
This vulnerability is identified as CVE-2026-34840. The attack can be initiated remotely. There is not any exploit available.
It is recommended to upgrade the affected component.