CVE-2026-34758Disclosure(hackerbay / oneuptime)

LOWCVSS 9.1 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch hackerbay oneuptime systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, unauthenticated access to Notification test and Phone Number management endpoints allows SMS/Call/Email/WhatsApp abuse and phone number purchase. This issue has been patched in version 10.0.42.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • oneuptime

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-04-03)
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
oneuptime

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-04-02: 1Mentions · 2026-04-03: 3Patch / Workaround · 2026-04-02: 1Technical Details · 2026-04-03: 304-0204-03
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-021
Patch1
2026-04-033
Disclosure3
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-34758 OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, unauthenticated access to Notification test and Phone Number management e… https://www.cve.org/CVERecord?id=CVE-2026-34758

    Post summary

    The post announces CVE‑2026‑34758, noting unauthenticated access in OneUptime before v10.0.42, but provides no PoC, exploit, patch, or evidence of active exploitation.

    00000157
    56.9K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-34758: OneUptime: Missing Authenticatio... Unauthenticated SMS/call/email spam cannon with phone number purchasing - attackers can drain budgets and flood targets... https://zerodaysignal.com/vulnerability/CVE-2026-34758 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE-2026-34758, describing an unauthenticated spam cannon that can drain budgets by purchasing phone numbers, but it offers no PoC, exploit code, patch information, or evidence of active exploitation.

    0000065
    197 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-34758 - Critical OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, unauthenticated access to Notification test and Phone Number management endpoints allows SMS/C... https://www.thehackerwire.com/vulnerability/CVE-2026-34758/ https://t.co/IfmGo3k8DH

    Post summary

    The post announces the critical CVE‑2026‑34758 in OneUptime, noting unauthenticated access to specific endpoints, but offers no proof‑of‑concept, exploit code, active usage, or patch details.

    0000060
    160 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-34758: CRITICAL] Cyber security alert: OneUptime platform had a vulnerability allowing unauthorized access to features. Make sure you update to version 10.0.42 to patch the issue.#cve,CVE-2026-34758,#cybersecurity https://cvefind.com/CVE-2026-34758

    Post summary

    The alert highlights CVE-2026-34758, a critical vulnerability in OneUptime that allows unauthorized feature access, and advises updating to version 10.0.42 to remediate the issue.

    0000056
    617 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphackerbayoneuptime---

Explore more