Missing Authentication Vulnerability in Dromara Skyeye's JobInfoController
CVE-2026-107779
9.3CRITICAL
What is CVE-2026-107779?
A missing authentication vulnerability exists in the JobInfoController endpoints of Dromara Skyeye, specifically in the bundled xxl-job-admin. Attackers can exploit this flaw by sending unauthorized POST requests to the /jobinfo/addAndStart endpoint with attacker-controlled glueSource. This can result in the execution of arbitrary commands on the host, or the ability to manipulate job processes, including stopping or deleting jobs. The flaw arises due to the improper annotation of permission limits within the code.
Affected Version(s)
skyeye 0 <= 003549ae5615bd114ba5bb8ddf6a8e8ead97c321
