Webhook Vulnerability in OneUptime's WhatsApp Notification System
CVE-2026-33143
8.7HIGH
What is CVE-2026-33143?
OneUptime, a service management solution, had a significant vulnerability prior to version 10.0.34 in its WhatsApp POST webhook handler. This issue allows attackers to exploit the lack of validation for the Meta/WhatsApp X-Hub-Signature-256 HMAC signature. Consequently, unauthenticated users can send forged webhook payloads, leading to improper manipulation of notification delivery statuses, suppression of alerts, and corruption of audit trails. Although this vulnerability was not present in the Slack webhook implementation, it has been addressed in the latest version, ensuring enhanced security for users.
Affected Version(s)
oneuptime < 10.0.34
