Cyber & AI intelligence
Wasteland.
Briefs indexed3091
Issues31
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-107779 2026-10-08

Dromara Skyeye CVE-2026-107779: Unauthenticated RCE via Bundled xxl-job-admin

"Dromara Skyeye bundles an xxl-job-admin component with job endpoints that need no authentication, so a remote attacker with no credentials can create and start jobs that run attacker-supplied shell, Python, or…"

Dromara Skyeye bundles an xxl-job-admin component with job endpoints that need no authentication, so a remote attacker with no credentials can create and start jobs that run attacker-supplied shell, Python, or PowerShell code on the executor host.

What Is It

CVE-2026-107779 is a missing-authentication flaw (CWE-306) in the xxl-job-admin component bundled with Dromara Skyeye. Endpoints in its JobInfoController are annotated with @PermissionLimit(limit = false), which turns off the permission check for those routes.

An unauthenticated attacker can POST a job of type GLUE_SHELL, GLUE_PYTHON, or GLUE_POWERSHELL with their own glueSource to /jobinfo/addAndStart. This runs commands on the executor host. The same exposed endpoints also let an attacker stop and delete jobs.

VulnCheck disclosed the issue. NVD published it on 2026-10-08 and lists its status as "Deferred."

Why It Matters

VulnCheck scores it 9.8 CRITICAL under CVSS 3.1 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) and 9.3 CRITICAL under CVSS 4.0. The attack:

A successful attack has high impact on confidentiality, integrity, and availability on the vulnerable system.

Based on the advisory's description, an attacker who can reach the xxl-job-admin interface of an affected deployment would likely be able to get command execution on a connected executor host and disrupt scheduled jobs. Real-world exposure depends on how a given deployment is set up, for example whether the admin interface is reachable from untrusted networks and whether executors are registered to run jobs. No public exploitation reports were found in the supplied data.

KEV status: The supplied CISA KEV data has no entry for this CVE. Active exploitation is not confirmed by KEV at this time.

What's Vulnerable

NVD lists no CPE configurations for this record.

Patch Status

The supplied NVD record names no fixed version or patched commit, and no CISA required action exists because there is no KEV listing. The affected range ends at commit 003549ae, with no remediation documented. Operators should watch the Skyeye repository and the linked GitHub issue for a fix. Check the VulnCheck advisory for any vendor guidance.

Sources