PT-2026-29569 · Unknown · Cronmaster
Qiaonpc
·
Published
2026-04-01
·
Updated
2026-04-02
·
CVE-2026-34072
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cr*nMaster versions prior to 2.2.0
Description
Cr*nMaster is a Cronjob management UI. Prior to version 2.2.0, an authentication bypass exists in the middleware. When the middleware’s session-validation fetch fails, unauthenticated requests with an invalid session cookie are incorrectly treated as authenticated. This can lead to unauthorized access to protected pages and the unauthorized execution of privileged Next.js Server Actions.
Recommendations
Update to version 2.2.0 or later.
Fix
Missing Authentication
Protection Mechanism Failure
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cronmaster