PT-2026-29876 · Twilio+1 · Twilio+1
Kodareef5
·
Published
2026-04-02
·
Updated
2026-04-03
·
CVE-2026-34759
CVSS v4.0
9.2
Critical
| Vector | AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
OneUptime versions prior to 10.0.42
Description
OneUptime, an open-source monitoring and observability platform, had multiple notification API endpoints registered without authentication middleware. This allowed an unauthenticated attacker to potentially purchase phone numbers on a victim's Twilio account and delete existing alerting numbers. The issue stemmed from a missing authentication check in the
/notification/ endpoints, while other endpoints correctly used authentication. A projectId leak from the public Status Page API contributed to the exploitability.Recommendations
Update to version 10.0.42 or later.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Oneuptime
Twilio