Description
Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 contains a missing authentication vulnerability in bundled xxl-job-admin JobInfoController endpoints annotated with @PermissionLimit(limit = false). Unauthenticated attackers can POST GLUE_SHELL, GLUE_PYTHON, or GLUE_POWERSHELL jobs with attacker-supplied glueSource to /jobinfo/addAndStart, executing commands on the executor host or stopping and deleting jobs.
Published: 2026-10-08
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Dromara Skyeye’s bundled xxl-job-admin component contains a missing authentication flaw in the JobInfoController endpoints controlling job execution. Attackers that can access these endpoints allow the creation or modification of jobs that run arbitrary shell, Python, or PowerShell code supplied via the glueSource parameter. The vulnerability enables direct execution of attacker‑supplied commands on the executor host, potentially compromising the entire system. The weakness is a classic missing authentication issue (CWE‑306).

Affected Systems

The affected product is dromara:skyeye’s xxl-job-admin module. The vulnerability exists in the code found in commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321; no specific version range is listed in the CNA data.

Risk and Exploitability

The CVSS score of 9.3 ranks this flaw as critical, indicating a high likelihood of severe impact if exploited. EPSS is not available, so no current exploitation probability estimate is published. It is not listed in the CISA KEV catalog, but the lack of authentication makes it trivially exploitable via unauthenticated HTTP POST requests to /jobinfo/addAndStart. The attack path requires only network reachability to the xxl-job-admin service and does not depend on privileged access or complex setup.

Generated by OpenCVE AI on October 8, 2026 at 21:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest security patch for the xxl-job-admin component from dromara
  • Configure the application to enforce authentication on all job management endpoints, ensuring @PermissionLimit annotations are correctly applied
  • Restrict network access to the xxl-job-admin service to trusted hosts or VPN only

Generated by OpenCVE AI on October 8, 2026 at 21:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Description Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 contains a missing authentication vulnerability in bundled xxl-job-admin JobInfoController endpoints annotated with @PermissionLimit(limit = false). Unauthenticated attackers can POST GLUE_SHELL, GLUE_PYTHON, or GLUE_POWERSHELL jobs with attacker-supplied glueSource to /jobinfo/addAndStart, executing commands on the executor host or stopping and deleting jobs.
Title Dromara Skyeye xxl-job-admin Missing Authentication on Job Endpoints Allows RCE
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-08T20:15:54.720Z

Reserved: 2026-10-08T20:02:30.396Z

Link: CVE-2026-107779

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-08T21:17:52.790

Modified: 2026-10-08T21:27:15.010

Link: CVE-2026-107779

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T21:30:18Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function