CVE 9.2 CRITICAL

OneUptime: Unauthenticated notification API endpoints – financial abuse via phone number purchase, service disruption, and SMTP credential exposure_CVE-2026-34759

9.2 / 10
CRITICAL
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Description

OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, multiple notification API endpoints are registered without authentication middleware, while sibling endpoints in the same codebase correctly use ClusterKeyAuthorization.isAuthorizedServiceMiddleware. These endpoints are externally reachable via the Nginx proxy at /notification/. Combined with a projectId leak from the public Status Page API, an unauthenticated attacker can purchase phone numbers on the victim's Twilio account and delete all existing alerting numbers. This issue has been patched in version 10.0.42.

Basic Information

ID CVE-2026-34759
Source GitHub_M
Published Apr 2, 2026 at 18:50
Modified Apr 3, 2026 at 12:58

Affected Product

Vendor OneUptime
Product oneuptime
Version < 10.0.42
Affected Versions OneUptime oneuptime < 10.0.42

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.