CVE 8.3 HIGH

cronmaster: Middleware authentication bypass enabling unauthorized page access and server-action execution_CVE-2026-34072

8.3 / 10
HIGH
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

Description

Cr*nMaster (cronmaster) is a Cronjob management UI with human readable syntax, live logging and log history for cronjobs. Prior to version 2.2.0, an authentication bypass in middleware allows unauthenticated requests with an invalid session cookie to be treated as authenticated when the middlewareโ€™s session-validation fetch fails. This can result in unauthorized access to protected pages and unauthorized execution of privileged Next.js Server Actions. This issue has been patched in version 2.2.0.

Basic Information

ID CVE-2026-34072
Source GitHub_M
Published Apr 1, 2026 at 16:51
Modified Apr 1, 2026 at 17:45

Affected Product

Vendor fccview
Product cronmaster
Version < 2.2.0
Affected Versions fccview cronmaster < 2.2.0

CWE Classification

References

๐Ÿ’ญ Join the Security Discussion

๐Ÿ”’ Your email address will not be published. Required fields are marked *

โš ๏ธ Please be respectful and constructive in your comments. Security discussions should remain professional.