Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 08 Oct 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 contains a missing authentication vulnerability in bundled xxl-job-admin JobInfoController endpoints annotated with @PermissionLimit(limit = false). Unauthenticated attackers can POST GLUE_SHELL, GLUE_PYTHON, or GLUE_POWERSHELL jobs with attacker-supplied glueSource to /jobinfo/addAndStart, executing commands on the executor host or stopping and deleting jobs. | |
| Title | Dromara Skyeye xxl-job-admin Missing Authentication on Job Endpoints Allows RCE | |
| Weaknesses | CWE-306 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-08T20:15:54.720Z
Reserved: 2026-10-08T20:02:30.396Z
Link: CVE-2026-107779
No data.
Status : Deferred
Published: 2026-10-08T21:17:52.790
Modified: 2026-10-08T21:27:15.010
Link: CVE-2026-107779
No data.
OpenCVE Enrichment
Updated: 2026-10-08T21:30:18Z