Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-72590

CRITICAL NVD
CVSS Score 9.8
Severity CRITICAL
Published Aug 10, 2026
Vendor unknown

Description

An OS command injection vulnerability in alseambusher/crontab-ui through 0.4.2 allows an unauthenticated remote attacker to inject arbitrary cron job entries by sending a crafted GET request to /crontab with URL-encoded newlines in the env_vars parameter.

References