Authentication Bypass in CronMaster Affects User Access
CVE-2026-34072

8.3HIGH

Key Information:

Vendor

Fccview

Vendor
CVE Published:
1 April 2026

What is CVE-2026-34072?

The CronMaster application, a user-friendly Cronjob management interface, is vulnerable to an authentication bypass. Prior to version 2.2.0, the middleware erroneously treated unauthenticated requests with invalid session cookies as authenticated due to a failure in session-validation fetch. This flaw can potentially enable unauthorized users to access restricted pages and execute privileged Next.js Server Actions. Users are strongly advised to update to version 2.2.0, where this vulnerability has been addressed.

Affected Version(s)

cronmaster < 2.2.0

References

CVSS V3.1

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.