Dromara Skyeye bundles an xxl-job-admin component with job endpoints that need no authentication, so a remote attacker with no credentials can create and start jobs that run attacker-supplied shell, Python, or PowerShell code on the executor host.
What Is It
CVE-2026-107779 is a missing-authentication flaw (CWE-306) in the xxl-job-admin component bundled with Dromara Skyeye. Endpoints in its JobInfoController are annotated with @PermissionLimit(limit = false), which turns off the permission check for those routes.
An unauthenticated attacker can POST a job of type GLUE_SHELL, GLUE_PYTHON, or GLUE_POWERSHELL with their own glueSource to /jobinfo/addAndStart. This runs commands on the executor host. The same exposed endpoints also let an attacker stop and delete jobs.
VulnCheck disclosed the issue. NVD published it on 2026-10-08 and lists its status as "Deferred."
Why It Matters
VulnCheck scores it 9.8 CRITICAL under CVSS 3.1 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) and 9.3 CRITICAL under CVSS 4.0. The attack:
- works over the network
- is low complexity
- needs no privileges
- needs no user interaction
A successful attack has high impact on confidentiality, integrity, and availability on the vulnerable system.
Based on the advisory's description, an attacker who can reach the xxl-job-admin interface of an affected deployment would likely be able to get command execution on a connected executor host and disrupt scheduled jobs. Real-world exposure depends on how a given deployment is set up, for example whether the admin interface is reachable from untrusted networks and whether executors are registered to run jobs. No public exploitation reports were found in the supplied data.
KEV status: The supplied CISA KEV data has no entry for this CVE. Active exploitation is not confirmed by KEV at this time.
What's Vulnerable
- Vendor/Product: Dromara Skyeye
- Affected range: All versions up to and including commit
003549ae5615bd114ba5bb8ddf6a8e8ead97c321(git-based versioning) - Component: Bundled
xxl-job-2.3.0/xxl-job-admin,JobInfoController.java - Weakness: CWE-306, Missing Authentication for Critical Function
NVD lists no CPE configurations for this record.
Patch Status
The supplied NVD record names no fixed version or patched commit, and no CISA required action exists because there is no KEV listing. The affected range ends at commit 003549ae, with no remediation documented. Operators should watch the Skyeye repository and the linked GitHub issue for a fix. Check the VulnCheck advisory for any vendor guidance.