---
id: CVE-2026-34759
title: OneUptime is an open-source monitoring and observability platform
summary: >-
  OneUptime is an open-source monitoring and observability platform. Prior to
  version 10.0.42, multiple notification API endpoints are registered without
  authentication middleware, while sibling endpoints in the same codebase
  correctly use…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-862
vendor: hackerbay
product: oneuptime
affected:
  - oneuptime < 10.0.42
patched:
  - oneuptime 10.0.42
published: '2026-04-02'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T22:10:00.247'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-34759'
references:
  - url: >-
      https://github.com/OneUptime/oneuptime/commit/9adbd04538714740506708d6fa610e433be4d2a4
    label: security-advisories@github.com
  - url: 'https://github.com/OneUptime/oneuptime/releases/tag/10.0.42'
    label: security-advisories@github.com
  - url: >-
      https://github.com/OneUptime/oneuptime/security/advisories/GHSA-6wc5-rhvj-cx7f
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00674
epssPercentile: 0.50517
ingestedAt: '2026-10-06T22:23:15.913Z'
---

## Overview

OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, multiple notification API endpoints are registered without authentication middleware, while sibling endpoints in the same codebase correctly use ClusterKeyAuthorization.isAuthorizedServiceMiddleware. These endpoints are externally reachable via the Nginx proxy at /notification/. Combined with a projectId leak from the public Status Page API, an unauthenticated attacker can purchase phone numbers on the victim's Twilio account and delete all existing alerting numbers. This issue has been patched in version 10.0.42.

## Affected

- `oneuptime < 10.0.42`

## Remediation

Upgrade past the affected range:

- `oneuptime 10.0.42`
