OneUptime is a solution for monitoring and managing online services. The resend-verification-code endpoint allows any authenticated user to trigger a verification code resend for any UserWhatsApp record by ID. Ownership is not validated (unlike the verify endpoint). This affects the UserWhatsAppAPI.ts endpoint and the UserWhatsAppService.ts service.
History

Tue, 10 Mar 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 10 Mar 2026 17:30:00 +0000

Type Values Removed Values Added
Description OneUptime is a solution for monitoring and managing online services. The resend-verification-code endpoint allows any authenticated user to trigger a verification code resend for any UserWhatsApp record by ID. Ownership is not validated (unlike the verify endpoint). This affects the UserWhatsAppAPI.ts endpoint and the UserWhatsAppService.ts service.
Title OneUptime has WhatsApp Resend Verification Authorization Bypass
Weaknesses CWE-285
CWE-307
CWE-639
CWE-862
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2026-03-10T17:06:33.581Z

Updated: 2026-03-10T17:59:05.359Z

Reserved: 2026-03-07T17:34:39.981Z

Link: CVE-2026-30959

cve-icon Vulnrichment

Updated: 2026-03-10T17:58:47.119Z

cve-icon NVD

Status : Received

Published: 2026-03-10T18:18:55.047

Modified: 2026-03-10T18:18:55.047

Link: CVE-2026-30959

cve-icon Redhat

No data.