Critical severity9.1NVD Advisory· Published Apr 2, 2026· Updated Apr 3, 2026
CVE-2026-34758
CVE-2026-34758
Description
OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, unauthenticated access to Notification test and Phone Number management endpoints allows SMS/Call/Email/WhatsApp abuse and phone number purchase. This issue has been patched in version 10.0.42.
Affected products
1Patches
19adbd0453871https://github.com/OneUptime/oneuptimevia nvd-ref
Vulnerability mechanics
Generated by null/stub on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.
References
3- github.com/OneUptime/oneuptime/commit/9adbd04538714740506708d6fa610e433be4d2a4nvdPatch
- github.com/OneUptime/oneuptime/security/advisories/GHSA-q253-6wcm-h8hpnvdExploitMitigationVendor Advisory
- github.com/OneUptime/oneuptime/releases/tag/10.0.42nvdRelease Notes
News mentions
0No linked articles in our index yet.