๐Ÿ” CVE Alert

CVE-2026-107779

CRITICAL 9.8

Dromara Skyeye xxl-job-admin Missing Authentication on Job Endpoints Allows RCE

CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th

Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 contains a missing authentication vulnerability in bundled xxl-job-admin JobInfoController endpoints annotated with @PermissionLimit(limit = false). Unauthenticated attackers can POST GLUE_SHELL, GLUE_PYTHON, or GLUE_POWERSHELL jobs with attacker-supplied glueSource to /jobinfo/addAndStart, executing commands on the executor host or stopping and deleting jobs.

CWE CWE-306
Vendor dromara
Product skyeye
Published Oct 8, 2026
Stay Ahead of the Next One

Get instant alerts for dromara skyeye

Be the first to know when new critical vulnerabilities affecting dromara skyeye are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

dromara / skyeye
0 โ‰ค 003549ae5615bd114ba5bb8ddf6a8e8ead97c321

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/dromara/skyeye/issues/29 github.com: https://github.com/dromara/skyeye/blob/003549ae5615bd114ba5bb8ddf6a8e8ead97c321/xxl-job-2.3.0/xxl-job-admin/src/main/java/com/xxl/job/admin/controller/JobInfoController.java#L183-L231 github.com: https://github.com/dromara/skyeye vulncheck.com: https://www.vulncheck.com/advisories/dromara-skyeye-xxl-job-admin-missing-authentication-on-job-endpoints-allows-rce

Credits

Ikram-4