Executive brief
OneUptime is an open-source monitoring and incident management platform. A flaw in its WhatsApp verification endpoint allows any authenticated user to trigger verification code resends for other users' WhatsApp accounts without ownership validation. This enables attackers to spam victims with unwanted verification codes, disrupt their service, and create social engineering opportunities.
Technical details
The vulnerability is an authorization bypass in the resend-verification-code API endpoint (UserWhatsAppAPI.ts). The endpoint accepts an itemId parameter and triggers a verification code resend without validating that the authenticated user owns the target WhatsApp record, unlike the corresponding verify endpoint which does perform ownership checks. An attacker with a valid project account and access token can specify any victim's UserWhatsApp itemId to trigger unsolicited resends. The attack requires authentication but no user interaction. Impact includes SMS/WhatsApp spam, denial-of-service against phone numbers, and account lockout scenarios. The fix was released in version 10.0.21, which adds ownership validation (item.userId must match authenticated user) and rate limiting.
Affected products
- OneUptime OneUptime < 10.0.21
Timeline
- 2026-03-10: disclosed
- 2026-03-10: patched: Version 10.0.21 released with fix