Impact
The vulnerability resides in xxl-job-admin's JobGroupController and allows improper privilege management, reflecting weaknesses identified as CWE-266 and CWE-269. An attacker can manipulate the system without proper authorization. Because the flaw is remote, it can be exploited over the network, giving the attacker the ability to perform unauthorized operations within the job scheduler's admin interface.
Affected Systems
The issue affects Xuxueli's xxl-job releases up to 3.4.2. All users running any version of the console built on the xxl-job framework are potentially exposed unless they have patched to a newer, fixed release.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate impact, but a public proof‑of‑concept has been released, making exploitation more feasible. The EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV. The likely attack vector is via unauthenticated or low‑privilege web requests; it does not allow arbitrary execution, but it can be used to schedule jobs, modify job groups, or access sensitive configuration data.
OpenCVE Enrichment