CVE-2026-72589: alseambusher crontab-ui - Unauthenticated RCE via Shell Injection in Imported Database hook Field
An OS command injection vulnerability in alseambusher/crontab-ui through 0.4.2 allows an unauthenticated remote attacker to execute arbitrary system commands by importing a crafted crontab database file. The POST /import endpoint accepts arbitrary .db files and overwrites the application database without validation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-72589?
CVE-2026-72589 has a severity rating of critical with a CVSS score of 9.8.
How do I fix CVE-2026-72589?
To fix CVE-2026-72589, upgrade to the latest version of alseambusher/crontab-ui that addresses the command injection vulnerability.
What type of attack is possible due to CVE-2026-72589?
CVE-2026-72589 allows unauthenticated remote attackers to execute arbitrary system commands via shell injection.
What can be exploited in CVE-2026-72589?
The vulnerability can be exploited by importing a crafted crontab database file through the /import endpoint.
Which versions of alseambusher/crontab-ui are affected by CVE-2026-72589?
CVE-2026-72589 affects versions of alseambusher/crontab-ui prior to 0.4.2.