Impact
The flaw is a lack of authentication checks on the Notification test and Phone Number management endpoints, allowing anyone to send messages, initiate calls, or purchase phone numbers through the platform. This is a classic authentication failure described as CWE‑306. An attacker could flood users with unwanted notifications or hijack the platform’s communication channels without obtaining any credentials.
Affected Systems
OneUptime, the open‑source monitoring and observability platform, is affected in all releases older than version 10.0.42. The vulnerability resides in the notification and phone‑number APIs, which are exposed over HTTP and can be accessed by unauthenticated clients.
Risk and Exploitability
The CVSS base score of 9.1 indicates a high‑severity risk. The EPSS score of below 1% suggests that exploitation is not yet widespread, and the issue is not included in the CISA KEV catalog. Attackers can exploit this remotely by sending unauthenticated HTTP requests to the vulnerable endpoints; no additional privileges or software are required.
OpenCVE Enrichment