Disclosure summary
OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, multiple notification API endpoints are registered without authentication middleware, while sibling endpoints in the same codebase correctly use ClusterKeyAuthorization.isAuthorizedServiceMiddleware. These endpoints are externally reachable via the Nginx proxy at /notification/. Combined with a projectId leak from the public Status Page API, an unauthenticated attacker can purchase phone numbers on the victim's Twilio account and delete all existing alerting numbers. This issue has been patched in version 10.0.42.
Source-reported weakness categories
CWE-862
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
NIST National Vulnerability Database · NVD-CVE-2026-34759
Open original source · Updated Oct 06, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
| Vendor | Product / association | Version / bounds |
|---|---|---|
| hackerbay | oneuptime | * {"versionEndExcluding":"10.0.42"} |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Patch
- github.com — Product, Release Notes
- github.com — Exploit, Mitigation, Vendor Advisory
PUBLISHED 2026-04-02T15:21:33-04:00
MODIFIED 2026-10-06T18:10:00-04:00
INGESTED 2026-10-08T12:40:21-04:00