PT-2026-31020 · Cronicle · Cronicle
Morimori-Dev
·
Published
2026-04-07
·
Updated
2026-04-08
·
CVE-2026-39401
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Cronicle versions prior to 0.9.111
Description
Cronicle is a multi-server task scheduler and runner with a web-based front-end UI. Before version 0.9.111, job (jb) child processes could include an
update event key in their JSON output. The server applied this directly to the parent event’s stored configuration without authorization checks. A low-privilege user capable of creating and running events could modify any event property, including webhook URLs and notification emails.Recommendations
Update to version 0.9.111 or later.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cronicle