CRITICAL🇵🇱 Wersja polska

CVE-2026-34758

CVSS 9.1v3.1pub. 2026-04-02upd. 2026-07-24

OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, unauthenticated access to Notification test and Phone Number management endpoints allows SMS/Call/Email/WhatsApp abuse and phone number purchase. This issue has been patched in version 10.0.42.

🤖 AI Analysis
How it works

The vulnerability classified as CWE-306 (missing authentication for critical function) consists in the fact that endpoints responsible for testing notifications and managing phone numbers do not require any authentication. An attacker with network access can directly send requests to these endpoints, initiating the sending of SMS messages, voice calls, emails or WhatsApp messages, as well as purchasing phone numbers at the platform operator's expense.

Impact

Attackers can abuse the platform to mass send messages through various communication channels (SMS, calls, email, WhatsApp) and generate costs through unauthorized purchase of phone numbers, as well as violate the confidentiality and integrity of notification configurations.

Mitigation & patch

OneUptime should be updated to version 10.0.42 or newer, where the vulnerability has been patched. The patch is available in the project repository on GitHub (commit 9adbd04538714740506708d6fa610e433be4d2a4) as well as the official 10.0.42 release.

Who is affected

Hackerbay OneUptime in versions prior to 10.0.42

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Hackerbay Oneuptime

    APP
    Hackerbay
    < 10.0.40
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-34759CRITICAL9.2PL ✓same product

Brak uwierzytelnienia w API powiadomień OneUptime — obejście autoryzacji

CVE-2026-35053CRITICAL9.2PL ✓same product

Brak uwierzytelnienia w endpointach workflow w OneUptime (RCE)

CVE-2026-33396CRITICAL9.9PL ✓same product

RCE w OneUptime — command injection przez Playwright w Synthetic Monitor

CVE-2026-32306CRITICAL9.9PL ✓same product

SQL Injection w OneUptime — nieautoryzowany dostęp do bazy i potencjalny RCE

CVE-2026-30921CRITICAL9.9PL ✓same product

OneUptime: RCE przez niebezpieczny Playwright sandbox w Synthetic Monitors