Junglewise Threat Intelligence

CVE-2026-72589: crontab-ui OS command injection in database import

CVE-2026-72589 · Severity: critical · CVSS 9.8 · Published 2026-08-10

Executive brief

crontab-ui is a web-based interface for managing cron jobs (automated system tasks). An attacker can upload a malicious database file through the import function without any authentication or validation, gaining the ability to execute arbitrary commands on the server with the privileges of the application. This could lead to complete system compromise, data theft, or use of the server for further attacks.

Technical details

This is an unauthenticated OS command injection vulnerability in the POST /import endpoint of crontab-ui versions up to 0.4.2. The vulnerable component accepts arbitrary .db files for database import without validating file contents or type, allowing an attacker to craft a malicious database file containing embedded shell commands. When imported, the application executes these commands. No authentication is required to access the /import endpoint, making this remotely exploitable over the network. An attacker gains arbitrary command execution with the application's privileges, potentially leading to full system takeover.

Affected products

  • alseambusher crontab-ui through 0.4.2

Timeline

  • 2026-08-10: disclosed

References

Related threats