Unauthorized Code Resend Vulnerability in OneUptime Monitoring Solution
CVE-2026-30959

5.3MEDIUM

Key Information:

Vendor

Oneuptime

Status
Vendor
CVE Published:
10 March 2026

What is CVE-2026-30959?

The OneUptime monitoring solution is vulnerable to an improper authorization issue whereby authenticated users can resend verification codes for any UserWhatsApp record without validating ownership. This affects both the UserWhatsAppAPI.ts endpoint and UserWhatsAppService.ts service, potentially allowing unauthorized users to exploit this functionality and gain access to sensitive user information. Users are advised to update to the latest version to mitigate this vulnerability.

Affected Version(s)

oneuptime < 10.0.21

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.