PatchSiren cyber security CVE debrief
CVE-2026-39401 jhuckaby CVE debrief
CVE-2026-39401 is a vulnerability in Cronicle, a multi-server task scheduler and runner. Prior to version 0.9.111, jb child processes can include an update_event key in their JSON output. The server applies this directly to the parent event's stored configuration without any authorization check. A low-privilege user who can create and run events can modify any event property, including webhook URLs and notification emails. This vulnerability could allow unauthorized modifications to event configurations, potentially leading to security breaches.
- Vendor
- jhuckaby
- Product
- Cronicle
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-07
- Original CVE updated
- 2026-07-20
- Advisory published
- 2026-04-07
- Advisory updated
- 2026-07-20
Who should care
Users of Cronicle versions prior to 0.9.111 should be aware of this vulnerability and take steps to mitigate it. This includes administrators and users with low-privilege access who can create and run events. Additionally, security teams and vulnerability management teams should review the affected scope and severity to ensure proper mitigation and remediation.
Technical summary
The vulnerability exists in Cronicle's handling of jb child processes, which can include an update_event key in their JSON output. This output is applied directly to the parent event's stored configuration without authorization checks, allowing low-privilege users to modify event properties. This could potentially allow unauthorized access or modifications to event configurations, including webhook URLs and notification emails.
Defensive priority
Medium
Recommended defensive actions
- Update Cronicle to version 0.9.111 or later
- Restrict access to event creation and modification to authorized users
- Monitor event configurations for unauthorized changes
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record was published on 2026-04-07T21:17:18.547Z and was last modified on 2026-07-20T20:10:00.110Z. The NVD entry is currently Analyzed. This information is based on the provided source corpus and may not reflect the full scope of the vulnerability. Users should verify the details with the official CVE record and NVD entry for the most accurate and up-to-date information.
Official resources
-
CVE-2026-39401 CVE record
CVE.org
-
CVE-2026-39401 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Exploit, Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-07T21:17:18.547Z and has not been modified since then. The NVD entry is currently Analyzed.