Junglewise Threat Intelligence

CVE-2026-41928: Vvveb information disclosure in cron controller

CVE-2026-41928 · Severity: medium · CVSS 5.3 · Published 2026-05-07

Technologies: Givanz VvvebJs. Vendors: Givanz.

Executive brief

Vvveb, an open-source content management system, contains a security flaw in its automated task scheduler. An unauthorized person can access a secret key that is normally hidden, which allows them to force the system to run background tasks at any time. This could disrupt normal operations or interfere with scheduled maintenance activities.

Technical details

An information disclosure vulnerability exists in the Vvveb cron controller (app/controller/cron.php) due to the presence of test code that inadvertently exposes the secret cron URL and key. An unauthenticated remote attacker can access the cron controller and retrieve the secret key from the HTTP response. With this key, the attacker can bypass intended access controls to trigger scheduled task execution (cron jobs) arbitrarily. The issue is classified as CWE-497 and was addressed in version 1.0.8.2 by removing the debug/test code that displayed the URL.

Affected products

  • givanz Vvveb < 1.0.8.2

Timeline

  • 2026-05-07: disclosed: Initial disclosure by VulnCheck
  • 2026-05-07: advisory: NVD publication date
  • 2026-05-07: patched: Fix committed to GitHub repository

References

Related threats