Description
A vulnerability was found in Xuxueli xxl-job up to 3.4.2. Affected by this issue is some unknown functionality of the file xxl-job-admin/src/main/java/com/xxl/job/admin/business/controller/JobGroupController.java. The manipulation results in improper privilege management. The attack may be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-12
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Patch ASAP
AI Analysis

Impact

The vulnerability resides in xxl-job-admin's JobGroupController and allows improper privilege management, reflecting weaknesses identified as CWE-266 and CWE-269. An attacker can manipulate the system without proper authorization. Because the flaw is remote, it can be exploited over the network, giving the attacker the ability to perform unauthorized operations within the job scheduler's admin interface.

Affected Systems

The issue affects Xuxueli's xxl-job releases up to 3.4.2. All users running any version of the console built on the xxl-job framework are potentially exposed unless they have patched to a newer, fixed release.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate impact, but a public proof‑of‑concept has been released, making exploitation more feasible. The EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV. The likely attack vector is via unauthenticated or low‑privilege web requests; it does not allow arbitrary execution, but it can be used to schedule jobs, modify job groups, or access sensitive configuration data.

Generated by OpenCVE AI on September 15, 2026 at 18:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest xxl-job patch that fixes the privilege handling in JobGroupController.
  • If an immediate patch is unavailable, restrict external access to the admin UI using firewall rules or reverse‑proxy authentication to limit exposure to trusted IP addresses.
  • Tight so that only privileged users can access group management endpoints, ensuring that users without appropriate roles cannot perform privileged actions.
  • Monitor admin‑UI logs for abnormal activity on JobGroupController endpoints.

Generated by OpenCVE AI on September 15, 2026 at 18:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 12 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in Xuxueli xxl-job up to 3.4.2. Affected by this issue is some unknown functionality of the file xxl-job-admin/src/main/java/com/xxl/job/admin/business/controller/JobGroupController.java. The manipulation results in improper privilege management. The attack may be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Xuxueli xxl-job JobGroupController.java privileges management
First Time appeared Xuxueli
Xuxueli xxl-job
Weaknesses CWE-266
CWE-269
CPEs cpe:2.3:a:xuxueli:xxl-job:*:*:*:*:*:*:*:*
Vendors & Products Xuxueli
Xuxueli xxl-job
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:P/I:N/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-14T15:56:40.271Z

Reserved: 2026-09-12T08:03:31.195Z

Link: CVE-2026-90487

cve-icon Vulnrichment

Updated: 2026-09-14T15:56:30.622Z

cve-icon NVD

Status : Deferred

Published: 2026-09-12T23:17:01.307

Modified: 2026-09-14T20:56:48.220

Link: CVE-2026-90487

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T18:30:14Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment

  • CWE-269

    Improper Privilege Management