CVE-2026-30959

MEDIUM

OneUptime - Auth Bypass

Title source: llm
STIX 2.1

Description

OneUptime is a solution for monitoring and managing online services. The resend-verification-code endpoint allows any authenticated user to trigger a verification code resend for any UserWhatsApp record by ID. Ownership is not validated (unlike the verify endpoint). This affects the UserWhatsAppAPI.ts endpoint and the UserWhatsAppService.ts service.

Scores

CVSS v3 5.0
EPSS 0.0002
EPSS Percentile 4.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-639 CWE-307 CWE-285 CWE-862
Status published
Products (1)
hackerbay/oneuptime < 10.0.21
Published Mar 10, 2026
Tracked Since Mar 11, 2026