Description
The WebAuthn authentication implementation does not store the challenge on the server side. Instead, the challenge is returned to the client and accepted back from the client request body during verification. This violates the WebAuthn specification (W3C Web Authentication Level 2, §13.4.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 10.0.11
References
Could your website be exposed too?
SmartScanner can check your website for OneUptime has WebAuthn 2FA bypass: server accepts client-supplied challenge instead of server-stored value, allowing cre and gives you actionable findings to investigate.
Start a free scanRelated Issues
- OneUptime has authorization bypass via client‑controlled is-multi-tenant-query header that leads to cross‑tenant data ex - CVE-2026-30956
- OneUptime has WhatsApp Resend Verification Authorization Bypass - CVE-2026-30959
- OneUptime has broken access control in GitHub App installation flow that allows unauthorized project binding - CVE-2026-30920
- OneUptime has Synthetic Monitor RCE via exposed Playwright browser object - CVE-2026-30957


