Impact
Dromara Skyeye’s bundled xxl-job-admin component contains a missing authentication flaw in the JobInfoController endpoints controlling job execution. Attackers that can access these endpoints allow the creation or modification of jobs that run arbitrary shell, Python, or PowerShell code supplied via the glueSource parameter. The vulnerability enables direct execution of attacker‑supplied commands on the executor host, potentially compromising the entire system. The weakness is a classic missing authentication issue (CWE‑306).
Affected Systems
The affected product is dromara:skyeye’s xxl-job-admin module. The vulnerability exists in the code found in commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321; no specific version range is listed in the CNA data.
Risk and Exploitability
The CVSS score of 9.3 ranks this flaw as critical, indicating a high likelihood of severe impact if exploited. EPSS is not available, so no current exploitation probability estimate is published. It is not listed in the CISA KEV catalog, but the lack of authentication makes it trivially exploitable via unauthenticated HTTP POST requests to /jobinfo/addAndStart. The attack path requires only network reachability to the xxl-job-admin service and does not depend on privileged access or complex setup.
OpenCVE Enrichment