CVE-2026-33143General(hackerbay / oneuptime)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch hackerbay oneuptime systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OneUptime is a solution for monitoring and managing online services. Prior to version 10.0.34, the WhatsApp POST webhook handler (/notification/whatsapp/webhook) processes incoming status update events without verifying the Meta/WhatsApp X-Hub-Signature-256 HMAC signature, allowing any unauthenticated attacker to send forged webhook payloads that manipulate notification delivery status records, suppress alerts, and corrupt audit trails. The codebase already implements proper signature verification for Slack webhooks. This issue has been patched in version 10.0.34.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-345

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • oneuptime

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-21); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
oneuptime

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-21: 2Mentions · 2026-03-24: 1Patch / Workaround · 2026-03-21: 1Technical Details · 2026-03-21: 1Technical Details · 2026-03-24: 103-2103-24
Signal classification3 categories
General
133.3%
Patch
133.3%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-212
General1Patch1
2026-03-241
Disclosure1
Full discourse3 posts
  • DailyCVE@dailycve
    Disclosure

    🔴 OneUptime, Missing Authentication, #CVE-2026-33143 (Critical) https://dailycve.com/oneuptime-missing-authentication-cve-2026-33143-critical/

    Post summary

    The post announces a critical missing authentication vulnerability in OneUptime (CVE‑2026‑33143) and links to a dailycve article for details, but provides no evidence of exploitation or mitigation.

    0000027
    173 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-33143 OneUptime is a solution for monitoring and managing online services. Prior to version 10.0.34, the WhatsApp POST webhook handler (/notification/whatsapp/webhook) proc… https://www.cve.org/CVERecord?id=CVE-2026-33143 ----- Traducción: CVE-2026-33143 One… http://infoflow.cloud`

    Post summary

    The tweet references CVE‑2026‑33143 and links to its CVE record, noting its presence in older OneUptime versions, but provides no further details on exploitation, remediation, or severity.

    0000031
    61 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-33143 OneUptime is a solution for monitoring and managing online services. Prior to version 10.0.34, the WhatsApp POST webhook handler (/notification/whatsapp/webhook) proc… https://www.cve.org/CVERecord?id=CVE-2026-33143

    Post summary

    CVE-2026-33143 targets OneUptime's WhatsApp webhook handler, and the vulnerability has been addressed in version 10.0.34.

    00000206
    56.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphackerbayoneuptime---

Explore more