PT-2026-31020 · Jhuckaby · Cronicle

Published

2026-04-07

·

Updated

2026-04-07

·

CVE-2026-39401

CVSS v4.0

5.3

Medium

AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Cronicle is a multi-server task scheduler and runner, with a web based front-end UI. Prior to 0.9.111, jb child processes can include an update event key in their JSON output. The server applies this directly to the parent event's stored configuration without any authorization check. A low-privilege user who can create and run events can modify any event property, including webhook URLs and notification emails. This vulnerability is fixed in 0.9.111.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-39401

Affected Products

Cronicle