Description
A vulnerability was determined in Xuxueli xxl-job up to 3.4.2. This affects the function GroovyClassLoader.parseClass of the file xxl-job-core/src/main/java/com/xxl/job/core/glue/GlueFactory.java. This manipulation causes code injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-12
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote code execution
Action: Immediate Patch
AI Analysis

Impact

A vulnerability in Xuxueli xxl-job enables arbitrary code execution through the GroovyClassLoader.parseClass method within GlueFactory.java. The flaw allows an attacker to inject Groovy code that is subsequently executed by the job scheduler, leading to complete compromise of the host system. The weakness aligns with code injection and code execution controls, as identified by CWE-74 and CWE-94.

Affected Systems

Versions of Xuxueli xxl-job up to and including 3.4.2 are affected-job core that exposes the GlueFactory functionality, such as the default web interface or API used for job configuration.

Risk and Exploitability

The CVSS base score of 5.3 indicates moderate severity, but the vulnerability is remotely exploitable and has publicly available proof‑of‑concepts. EPSS score of 0.00228 (<1%) indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. An attacker that can reach the job configuration endpoint can provide malicious compile and run without additional input validation, resulting in full remote code execution.

Generated by OpenCVE AI on September 15, 2026 at 17:47 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to the latest version of Xuxueli xxl-job that contains the patch for the GroovyClassLoader.parseClass flaw.
  • Restrict network access to the job configuration API or web interface, allowing only trusted administrators to submit jobs and code.
  • Implement input validation or remove the ability to submit arbitrary Groovy code, ensuring that only pre‑approved scripts are executed by the scheduler.

Generated by OpenCVE AI on September 15, 2026 at 17:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 12 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in Xuxueli xxl-job up to 3.4.2. This affects the function GroovyClassLoader.parseClass of the file xxl-job-core/src/main/java/com/xxl/job/core/glue/GlueFactory.java. This manipulation causes code injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Title Xuxueli xxl-job GlueFactory.java GroovyClassLoader.parseClass code injection
First Time appeared Xuxueli
Xuxueli xxl-job
Weaknesses CWE-74
CWE-94
CPEs cpe:2.3:a:xuxueli:xxl-job:*:*:*:*:*:*:*:*
Vendors & Products Xuxueli
Xuxueli xxl-job
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T14:01:04.709Z

Reserved: 2026-09-12T08:03:34.563Z

Link: CVE-2026-90488

cve-icon Vulnrichment

Updated: 2026-09-15T13:42:32.324Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T00:17:06.680

Modified: 2026-09-15T15:17:27.203

Link: CVE-2026-90488

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T18:00:17Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')