PT-2026-62413 · Git+1 · Xxl-Job

·

CVE-2026-65316

·

Published

2026-07-21

·

Updated

2026-07-21

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions XXL-Job version 2.4.2
Description An insecure direct object reference allows authenticated users to read execution log content from job groups they are not authorized to access. By supplying arbitrary sequential values to the logId parameter at the '/logDetailCat' endpoint, attackers can enumerate log records across all job groups. This process bypasses the permission checks implemented in the '/logDetailPage' endpoint, enabling the retrieval of sensitive log content from restricted groups.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. Avoid using the logId parameter in the '/logDetailCat' endpoint until the issue is resolved.

Exploit

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-65316

Affected Products

Xxl-Job