PT-2026-29876 · Twilio+1 · Twilio+1

Kodareef5

·

Published

2026-04-02

·

Updated

2026-04-03

·

CVE-2026-34759

CVSS v4.0

9.2

Critical

VectorAV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OneUptime versions prior to 10.0.42
Description OneUptime, an open-source monitoring and observability platform, had multiple notification API endpoints registered without authentication middleware. This allowed an unauthenticated attacker to potentially purchase phone numbers on a victim's Twilio account and delete existing alerting numbers. The issue stemmed from a missing authentication check in the /notification/ endpoints, while other endpoints correctly used authentication. A projectId leak from the public Status Page API contributed to the exploitability.
Recommendations Update to version 10.0.42 or later.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-34759

Affected Products

Oneuptime
Twilio