PULSE
LIVE59signals / 24h
FEED
ransomthegentlemen reclama a DHC · JP · Not Foundransomthegentlemen reclama a INKA Group GmbH Co · DE · Manufacturingransomthegentlemen reclama a Vitex Pharmaceuticals · Healthcareransomthegentlemen reclama a Mdj Management · Otherransomthegentlemen reclama a Hst · US · Not Foundransomthegentlemen reclama a Groupe BPCE · VN · Financial Servicesransomthegentlemen reclama a Axson Teknik · SE · Manufacturingransomthegentlemen reclama a Ponti · PL · Otherransomthegentlemen reclama a Godollo · HU · Agriculture and Food Productionransomthegentlemen reclama a Hoang Chiropractic Center · US · Healthcareransomthegentlemen reclama a aZaaS · US · Technologyransomthegentlemen reclama a National Furniture Outlet · US · Retail & E-Commerceransomthegentlemen reclama a TESI · IT · Not Foundransomthegentlemen reclama a Intranet Gov Brasil · BR · Government & Defenseransomthegentlemen reclama a DHC · JP · Not Foundransomthegentlemen reclama a INKA Group GmbH Co · DE · Manufacturingransomthegentlemen reclama a Vitex Pharmaceuticals · Healthcareransomthegentlemen reclama a Mdj Management · Otherransomthegentlemen reclama a Hst · US · Not Foundransomthegentlemen reclama a Groupe BPCE · VN · Financial Servicesransomthegentlemen reclama a Axson Teknik · SE · Manufacturingransomthegentlemen reclama a Ponti · PL · Otherransomthegentlemen reclama a Godollo · HU · Agriculture and Food Productionransomthegentlemen reclama a Hoang Chiropractic Center · US · Healthcareransomthegentlemen reclama a aZaaS · US · Technologyransomthegentlemen reclama a National Furniture Outlet · US · Retail & E-Commerceransomthegentlemen reclama a TESI · IT · Not Foundransomthegentlemen reclama a Intranet Gov Brasil · BR · Government & Defense
← All CVEs
CVE WatchJul 20, 2026

CVE-2026-39401

Cronicle is a multi-server task scheduler and runner, with a web based front-end UI. Prior to 0.9.111, jb child processes can include an upd

CVSS

5.4

Medium

EPSS

0.2%

p8

KEV

Exploit Today

2

0-100

Published: Apr 7, 2026 · Last modified: Jul 20, 2026 · CWE-862

EPSS · 30d
0.2%EPSS · 30 days0.2%
2026-07-092026-08-05
Technical description

Cronicle is a multi-server task scheduler and runner, with a web based front-end UI. Prior to 0.9.111, jb child processes can include an update_event key in their JSON output. The server applies this directly to the parent event's stored configuration without any authorization check. A low-privilege user who can create and run events can modify any event property, including webhook URLs and notification emails. This vulnerability is fixed in 0.9.111.

Official references
Related CVEs
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-143659.8 CRI
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to change the password of arbitrary user accounts, including administrators, which can be leveraged to gain access to those accounts.5h
CVE-2026-119076.5 MED
The Stream plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.2.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to access all Stream activity records via the Heartbeat API.5h
CVE-2026-6566710.0 CRI
Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.8h
CVE-2026-628309.9 CRI
Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.10h
CVE-2026-706367.5 HIG
Flowise through 3.1.4 contains an authentication bypass vulnerability that allows unauthenticated attackers to access the OAuth2 credential refresh endpoint by exploiting prefix-based whitelist matching in the authentication middleware defined in packages/server/src/utils/constants.ts. Attackers can send a POST request to the oauth2-credential refresh route with a trailing credential identifier to bypass all authentication and authorization checks, triggering unauthorized OAuth token rotation against credentials belonging to any workspace and potentially disrupting dependent OAuth integrations. This is a bypass of CVE-2026-41273.12h
CVE-2026-676217.6 HIG
Flowise through 3.1.4 contains a missing authorization vulnerability that allows authenticated workspace members to perform unauthorized document store operations by accessing unprotected mutation endpoints. Attackers holding only view-level permissions can send direct HTTP requests to the upsert and refresh document store routes to trigger document ingestion, refresh vector database contents, consume embedding API credits, and modify knowledge bases used by downstream chatflows.12h