Authentication Bypass in CronMaster Affects User Access
CVE-2026-34072
8.3HIGH
What is CVE-2026-34072?
The CronMaster application, a user-friendly Cronjob management interface, is vulnerable to an authentication bypass. Prior to version 2.2.0, the middleware erroneously treated unauthenticated requests with invalid session cookies as authenticated due to a failure in session-validation fetch. This flaw can potentially enable unauthorized users to access restricted pages and execute privileged Next.js Server Actions. Users are strongly advised to update to version 2.2.0, where this vulnerability has been addressed.
Affected Version(s)
cronmaster < 2.2.0
