CVE-2026-39401 Details
Description
Cronicle is a multi-server task scheduler and runner, with a web based front-end UI. Prior to 0.9.111, jb child processes can include an update_event key in their JSON output. The server applies this directly to the parent event's stored configuration without any authorization check. A low-privilege user who can create and run events can modify any event property, including webhook URLs and notification emails. This vulnerability is fixed in 0.9.111.
A privilege escalation vulnerability exists in Cronicle, a multi-server task scheduler, in versions prior to 0.9.111. Low-privilege users who can create and run events can exploit this vulnerability by including an 'update_event' key in the JSON output of their job scripts. The server processes this key without any authorization checks, allowing the user to modify various event properties, such as webhook URLs and notification emails. This unauthorized access could lead to interception of alerts and exfiltration of sensitive job data, including script contents and internal network information.
Users should update to Cronicle version 0.9.111 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/jhuckaby/Cronicle/security/advisories/GHSA-5j3v-cq96-xw6v | CISA-ADP | ExploitVendor Advisory |
| https://github.com/jhuckaby/Cronicle/security/advisories/GHSA-5j3v-cq96-xw6v | [email protected] | ExploitVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| cronicle cronicle | < 0.9.111 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 20, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 15, 2026 | Initial Analysis | [email protected] |
| Apr 8, 2026 | CVE Modified | CISA-ADP |
| Apr 7, 2026 | New CVE Received | [email protected] |