PT-2026-24191 · Oneuptime · Oneuptime

Aryma-F4

·

Published

2026-03-10

·

Updated

2026-03-16

·

CVE-2026-30959

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L
Name of the Vulnerable Software and Affected Versions OneUptime (affected versions not specified)
Description The 'resend-verification-code' endpoint in OneUptime allows an authenticated user to trigger a verification code resend for any UserWhatsApp record by its itemId. A critical flaw exists because the system does not validate ownership of the UserWhatsApp record before allowing the resend operation, unlike the 'verify' endpoint. This impacts the UserWhatsAppAPI.ts endpoint and the UserWhatsAppService.ts service. An attacker with a valid account and access token can exploit this to repeatedly request verification codes for any user's WhatsApp number, potentially leading to spam, denial-of-service, social engineering attacks, or account lockout. The vulnerable API endpoint is /api/user-whats-app/resend-verification-code, which accepts a JSON payload containing the itemId of the target UserWhatsApp record. The vulnerable parameter is itemId.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Missing Authorization

Improper Restriction of Excessive Authentication Attempts

IDOR

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-30959
GHSA-CW6X-MW64-Q6PV

Affected Products

Oneuptime