PT-2026-31020 · Cronicle · Cronicle

Morimori-Dev

·

Published

2026-04-07

·

Updated

2026-04-08

·

CVE-2026-39401

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Cronicle versions prior to 0.9.111
Description Cronicle is a multi-server task scheduler and runner with a web-based front-end UI. Before version 0.9.111, job (jb) child processes could include an update event key in their JSON output. The server applied this directly to the parent event’s stored configuration without authorization checks. A low-privilege user capable of creating and running events could modify any event property, including webhook URLs and notification emails.
Recommendations Update to version 0.9.111 or later.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-39401

Affected Products

Cronicle