CVE-2026-30959Medium· 5.0▾ SunlitOneUptime is a solution for monitoring and managing online services. The resend-verification-code endpoint allows any authenticated user to trigger a verification code resend for any UserWhatsApp record by ID. Ownership is not validated …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
OneUptime is a solution for monitoring and managing online services. The resend-verification-code endpoint allows any authenticated user to trigger a verification code resend for any UserWhatsApp record by ID. Ownership is not validated (unlike the verify endpoint). This affects the UserWhatsAppAPI.ts endpoint and the UserWhatsAppService.ts service.
oneuptime < 10.0.21Upgrade past the affected range:
oneuptime 10.0.21Connected by shared product, vendor, weakness, or advisory.
CVE-2026-30956Critical· 9.9OneUptime is a solution for monitoring and managing online services
CVE-2026-30957Critical· 9.9OneUptime is a solution for monitoring and managing online services
CVE-2026-30958High· 7.2OneUptime is a solution for monitoring and managing online services
CVE-2026-34759High· 8.1OneUptime is an open-source monitoring and observability platform
CVE-2026-33396Critical· 9.9OneUptime is an open-source monitoring and observability platform
CVE-2026-33142High· 8.1OneUptime is a solution for monitoring and managing online services