CVE-2026-34759High· 8.1▾ TwilightOneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, multiple notification API endpoints are registered without authentication middleware, while sibling endpoints in the same codebase correctly use…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 44.6 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.7%
OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, multiple notification API endpoints are registered without authentication middleware, while sibling endpoints in the same codebase correctly use ClusterKeyAuthorization.isAuthorizedServiceMiddleware. These endpoints are externally reachable via the Nginx proxy at /notification/. Combined with a projectId leak from the public Status Page API, an unauthenticated attacker can purchase phone numbers on the victim's Twilio account and delete all existing alerting numbers. This issue has been patched in version 10.0.42.
oneuptime < 10.0.42Upgrade past the affected range:
oneuptime 10.0.42Connected by shared product, vendor, weakness, or advisory.
CVE-2026-34758Critical· 9.1OneUptime is an open-source monitoring and observability platform
CVE-2026-35053Critical· 9.8OneUptime is an open-source monitoring and observability platform
CVE-2026-34840High· 8.1OneUptime is an open-source monitoring and observability platform
CVE-2025-12925High· 7.3A security flaw has been discovered in rymcu forest up to de53ce79db9faa2efc4e79ce1077a302c42a1224
CVE-2025-48614Medium· 4.6In rebootWipeUserData of RecoverySystem.java, there is a possible way to factory reset the device while in DSU mode due to a missing permission check
CVE-2025-48604Medium· 5.5In multiple locations, there is a possible way to read files from another user due to a missing permission check