---
id: CVE-2026-33143
title: OneUptime is a solution for monitoring and managing online services
summary: >-
  OneUptime is a solution for monitoring and managing online services. Prior to
  version 10.0.34, the WhatsApp POST webhook handler
  (/notification/whatsapp/webhook) processes incoming status update events
  without verifying the Meta/WhatsApp…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'
cwe:
  - CWE-345
vendor: hackerbay
product: oneuptime
affected:
  - oneuptime < 10.0.34
patched:
  - oneuptime 10.0.34
published: '2026-03-20'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T08:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-33143'
references:
  - url: >-
      https://github.com/OneUptime/oneuptime/security/advisories/GHSA-g5ph-f57v-mwjc
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00198
epssPercentile: 0.08754
ingestedAt: '2026-10-07T08:20:03.902Z'
---

## Overview

OneUptime is a solution for monitoring and managing online services. Prior to version 10.0.34, the WhatsApp POST webhook handler (/notification/whatsapp/webhook) processes incoming status update events without verifying the Meta/WhatsApp X-Hub-Signature-256 HMAC signature, allowing any unauthenticated attacker to send forged webhook payloads that manipulate notification delivery status records, suppress alerts, and corrupt audit trails. The codebase already implements proper signature verification for Slack webhooks. This issue has been patched in version 10.0.34.

## Affected

- `oneuptime < 10.0.34`

## Remediation

Upgrade past the affected range:

- `oneuptime 10.0.34`
