Junglewise Threat Intelligence

CVE-2026-72590: alseambusher crontab-ui OS command injection via env_vars

CVE-2026-72590 · Severity: critical · CVSS 9.8 · Published 2026-08-10

Executive brief

crontab-ui is a web application for managing cron jobs. An unauthenticated remote attacker can inject arbitrary cron job entries by sending a specially crafted request, potentially gaining the ability to execute arbitrary system commands with the privileges of the application.

Technical details

An OS command injection vulnerability exists in crontab-ui through version 0.4.2 in the /crontab endpoint's env_vars parameter. The vulnerability is triggered by sending a GET request with URL-encoded newlines (%0A) in the env_vars parameter, allowing an attacker to inject arbitrary cron job directives into the crontab file. The application fails to properly sanitize or validate newline characters in user-supplied input before writing to the crontab configuration. No authentication is required to exploit this vulnerability. An attacker can inject malicious cron jobs that execute arbitrary commands when the cron daemon processes the modified crontab file.

Affected products

  • alseambusher crontab-ui through 0.4.2

Timeline

  • 2026-08-10: disclosed

References

Related threats