CVE-2026-30959: Hackerbay Oneuptime
Medium severity, CVSS 5.0. EPSS: 0.4% chance of exploitation in the next 30 days.
OneUptime is a solution for monitoring and managing online services. The resend-verification-code endpoint allows any authenticated user to trigger a verification code resend for any UserWhatsApp record by ID. Ownership is not validated (unlike the verify endpoint). This affects the UserWhatsAppAPI.ts endpoint and the UserWhatsAppService.ts service.
Affected products
- Hackerbay Oneuptime: before 10.0.21 (fixed in 10.0.21)
Published 2026-03-10. Last modified 2026-10-07.