PT-2026-29569 · Unknown · Cronmaster
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cr*nMaster versions prior to 2.2.0
Description
Cr*nMaster is a Cronjob management UI. Prior to version 2.2.0, an authentication bypass exists in the middleware. When the middleware’s session-validation fetch fails, unauthenticated requests with an invalid session cookie are incorrectly treated as authenticated. This can lead to unauthorized access to protected pages and the unauthorized execution of privileged Next.js Server Actions.
Recommendations
Update to version 2.2.0 or later.
Exploit
Fix
Protection Mechanism Failure
Improper Authentication
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cronmaster