Description
The resend-verification-code endpoint allows any authenticated user to trigger a verification code resend for any UserWhatsApp record by ID. Ownership is not validated (unlike the verify endpoint).
Recommendation
Update the @oneuptime/common package to the latest compatible version. Followings are version details:
- Affected version(s): < 10.0.21
- Patched version(s): 10.0.21
References
Could your website be exposed too?
SmartScanner can check your website for OneUptime has WhatsApp Resend Verification Authorization Bypass and gives you actionable findings to investigate.
Start a free scanRelated Issues
- OneUptime has authorization bypass via client‑controlled is-multi-tenant-query header that leads to cross‑tenant data ex - CVE-2026-30956
- OneUptime has WebAuthn 2FA bypass: server accepts client-supplied challenge instead of server-stored value, allowing cre - CVE-2026-28787
- Axios has a Patch Bypass: Proxy-Authorization Header Injection via Prototype Pollution — Incomplete Null-Prototype Fix - CVE-2026-44489
- Clerk has an authorization bypass when combining organization, billing, or reverification checks - CVE-2026-42349


