PT-2026-108202 · Unknown+1 · Xxl-Job-Admin+1

·

CVE-2026-107779

·

Published

2026-10-08

·

Updated

2026-10-09

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dromara Skyeye versions prior to commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321
Description A missing authentication issue exists in the bundled xxl-job-admin JobInfoController endpoints annotated with @PermissionLimit(limit = false). Unauthenticated attackers can send requests to the /jobinfo/addAndStart endpoint by providing attacker-supplied glueSource for GLUE SHELL, GLUE PYTHON, or GLUE POWERSHELL jobs. This allows for remote code execution on the executor host, as well as the ability to stop and delete jobs.
Recommendations Update Dromara Skyeye to a version including commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321.

Fix

RCE

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-107779

Affected Products

Skyeye
Xxl-Job-Admin