Missing Authentication Vulnerability in Dromara Skyeye's JobInfoController
CVE-2026-107779

9.3CRITICAL

Key Information:

Vendor

Dromara

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-107779?

A missing authentication vulnerability exists in the JobInfoController endpoints of Dromara Skyeye, specifically in the bundled xxl-job-admin. Attackers can exploit this flaw by sending unauthorized POST requests to the /jobinfo/addAndStart endpoint with attacker-controlled glueSource. This can result in the execution of arbitrary commands on the host, or the ability to manipulate job processes, including stopping or deleting jobs. The flaw arises due to the improper annotation of permission limits within the code.

Affected Version(s)

skyeye 0 <= 003549ae5615bd114ba5bb8ddf6a8e8ead97c321

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ikram-4
.