Junglewise Threat Intelligence

CVE-2026-34758: OneUptime missing authentication in Notification and Phone Number endpoints

CVE-2026-34758 · Severity: critical · CVSS 9.1 · Published 2026-04-02

Technologies: OneUptime. Vendors: OneUptime.

Executive brief

OneUptime, an open-source monitoring and observability platform, contains a critical security flaw where several notification and phone management features were left unprotected. An unauthorized person could use the platform to send mass SMS, WhatsApp messages, or emails, and even purchase new phone numbers using the company's linked Twilio or SMTP accounts. This could lead to significant financial charges, the theft of email server credentials, and damage to the organization's reputation through spam or fraudulent communications.

Technical details

A missing authentication vulnerability (CWE-306) exists in the Notification API of OneUptime. Multiple endpoints, including those for testing WhatsApp, SMS, and SMTP configurations, as well as phone number management (search, purchase, and release), failed to implement the 'isAuthorizedServiceMiddleware' check. An unauthenticated remote attacker can exploit these endpoints to send arbitrary communications or manipulate Twilio/SMTP resources. Furthermore, because the backend service uses 'isRoot: true' when fetching configurations for these tests, it bypasses internal permission checks, potentially exposing sensitive credentials like SMTP passwords and Twilio AuthTokens. The vulnerability is resolved in version 10.0.42 by applying proper authentication middleware to all affected routes.

Affected products

  • OneUptime OneUptime < 10.0.42

Timeline

  • 2026-03-30: advisory: GitHub Security Advisory published
  • 2026-03-31: patched: Version 10.0.42 released
  • 2026-04-02: disclosed: CVE-2026-34758 published

References

Related threats