Unauthorized Code Resend Vulnerability in OneUptime Monitoring Solution
CVE-2026-30959
5.3MEDIUM
What is CVE-2026-30959?
The OneUptime monitoring solution is vulnerable to an improper authorization issue whereby authenticated users can resend verification codes for any UserWhatsApp record without validating ownership. This affects both the UserWhatsAppAPI.ts endpoint and UserWhatsAppService.ts service, potentially allowing unauthorized users to exploit this functionality and gain access to sensitive user information. Users are advised to update to the latest version to mitigate this vulnerability.
Affected Version(s)
oneuptime < 10.0.21
