
CVE-2026-39400 Cronicle is a multi-server task scheduler and runner, with a web based front-end UI. Prior to 0.9.111, a non-admin user with create_events and run_events privileges c… https://www.cve.org/CVERecord?id=CVE-2026-39400
Post summary
The post announces CVE-2026-39400, noting a Privilege Escalation flaw in Cronicle that allows non‑admin users to create and run events before v0.9.111, without mentioning PoC or patches.

