CVE-2026-34759
HIGHOneUptime: Unauthenticated notification API endpoints - financial abuse via phone number purchase, service disruption, and SMTP credential exposure
Title source: cnaDescription
OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, multiple notification API endpoints are registered without authentication middleware, while sibling endpoints in the same codebase correctly use ClusterKeyAuthorization.isAuthorizedServiceMiddleware. These endpoints are externally reachable via the Nginx proxy at /notification/. Combined with a projectId leak from the public Status Page API, an unauthenticated attacker can purchase phone numbers on the victim's Twilio account and delete all existing alerting numbers. This issue has been patched in version 10.0.42.
References (3)
Core 3
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/OneUptime/oneuptime/security/advisories/GHSA-6wc5-rhvj-cx7f
X_Refsource_Misc x_refsource_misc
https://github.com/OneUptime/oneuptime/commit/9adbd04538714740506708d6fa610e433be4d2a4
X_Refsource_Misc x_refsource_misc
https://github.com/OneUptime/oneuptime/releases/tag/10.0.42
Scores
CVSS v3
8.1
EPSS
0.0060
EPSS Percentile
44.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-862
Status
published
Products (2)
hackerbay/oneuptime
< 10.0.42
OneUptime/oneuptime
< 10.0.42
Published
Apr 02, 2026
Tracked Since
Apr 03, 2026