SECURITYCRITICALCVE-2026-107779

CVE-2026-107779: Dromara Skyeye Unauthenticated RCE via Bundled xxl-job-admin

Unauthenticated POSTs to Skyeye's bundled xxl-job-admin let attackers run arbitrary GLUE_SHELL, GLUE_PYTHON, or GLUE_POWERSHELL jobs for remote code execution.

Dylan H.

Security Team

October 9, 2026
6 min read
CVE-2026-107779: Dromara Skyeye Unauthenticated RCE via Bundled xxl-job-admin

Critical severity

Rated critical. Prioritise patching — see the remediation guidance below.

Affected Products

  • Dromara Skyeye (through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321)

Overview

CVE-2026-107779 is a critical missing-authentication vulnerability (CVSS 9.8) in Dromara Skyeye, affecting the xxl-job-admin component it bundles for distributed task scheduling. Several endpoints in JobInfoController — including /jobinfo/addJob, /jobinfo/addAndStart, /jobinfo/removeJob, and /jobinfo/startJob — are annotated @PermissionLimit(limit = false), which skips the application's normal authentication checks entirely. Because xxl-job's "GLUE" feature lets an admin define a job's business logic as raw script content (shell, Python, PowerShell, Groovy, PHP, or Node.js) stored and executed directly by the scheduler, an unauthenticated attacker who can reach these endpoints can submit a job with attacker-controlled script content and have it executed on the job executor host — resulting in remote code execution with no credentials and no user interaction required.


Technical Details

FieldValue
CVE IDCVE-2026-107779
SeverityCritical (CVSS 3.1: 9.8, CVSS 4.0: 9.3)
Attack VectorNetwork
Attack ComplexityLow
AuthenticationNone
User InteractionNone
ScopeUnchanged
ImpactConfidentiality: High, Integrity: High, Availability: High (arbitrary code execution on the job executor host)
Affected VersionsDromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 (bundled xxl-job-admin 2.3.0)
Assigned ByVulnCheck
Disclosed2026-10-08

How It Works

The @PermissionLimit(limit = false) Bypass

xxl-job-admin's JobInfoController uses a @PermissionLimit annotation to mark which routes require an authenticated admin session. Several job-management endpoints — addJob, addAndStart, removeJob, and startJob — are marked @PermissionLimit(limit = false), which was apparently intended to exempt specific, low-risk routes from the check under controlled circumstances. In Skyeye's bundled copy of xxl-job-admin, that exemption instead applies to endpoints that create, start, and delete job definitions — core administrative functions that should never be reachable without a session.

Combined with xxl-job's commonly-deployed default of an empty xxl.job.accessToken, this means the job-management API is effectively open to anyone who can reach it over the network, with no login and no token required.

Abusing GLUE Jobs for Code Execution

xxl-job's "GLUE" mode lets a job's logic be submitted as raw source code (glueSource) in a chosen language (glueType), rather than compiled Java packaged with the executor. Supported glueType values reported in the disclosure include GLUE_SHELL, GLUE_PYTHON, GLUE_POWERSHELL, GROOVY, PHP, and NODEJS. Because the admin server trusts whatever script content is supplied and hands it to the executor to run, an attacker who can POST a job definition can embed arbitrary shell, Python, or PowerShell commands directly in glueSource.

Publicly described proof-of-concept behavior: with the default empty xxl.job.accessToken, an unauthenticated POST /jobinfo/addAndStart request with glueType: GLUE_SHELL and glueSource: echo pwn creates and immediately runs the job, with the output visible in the xxl-job UI and the executor's logs — confirming command execution on the executor host. The same primitive generalizes to any shell, Python, or PowerShell payload the attacker chooses, and the removeJob/startJob endpoints let the same unauthenticated actor also stop, delete, or re-trigger existing scheduled jobs.


Impact Assessment

Impact AreaDescription
ConfidentialityFull — arbitrary script execution can read any file or data accessible to the executor process
IntegrityFull — attacker-controlled jobs can modify application data, configuration, or deployed code
AvailabilityFull — the same unauthenticated endpoints can stop or delete legitimate scheduled jobs, disrupting dependent automation
Blast RadiusAny host running the bundled xxl-job executor that can reach the exposed admin API, plus anything that executor process can touch

Who Is At Risk

  • Any deployment of Dromara Skyeye (through the affected commit) with its bundled xxl-job-admin reachable from an untrusted network, including the public internet
  • Installations that left xxl.job.accessToken at its empty/default value — the common case for this component
  • Organizations using Skyeye's job scheduler to run operational automation, since a compromised executor host can be a pivot point into adjacent infrastructure

Potential Attack Chain

  1. Discovery — Attacker identifies a reachable xxl-job-admin instance bundled with Skyeye, typically by scanning for the admin web UI or API paths on exposed hosts.
  2. Unauthenticated Access — Attacker sends requests directly to /jobinfo/addAndStart (or the sibling endpoints) without any session cookie, API key, or accessToken — the @PermissionLimit(limit = false) annotation lets the request through.
  3. Malicious Job Submission — Attacker submits a job with glueType: GLUE_SHELL (or GLUE_PYTHON/GLUE_POWERSHELL) and a glueSource payload containing arbitrary commands.
  4. Remote Code Execution — The executor runs the submitted script, giving the attacker command execution with the privileges of the executor process.
  5. Post-Exploitation — The attacker can establish persistence via recurring jobs, exfiltrate data, pivot laterally, or use removeJob/startJob to sabotage legitimate scheduled automation.

Mitigation

Immediate Actions

  • Set a strong xxl.job.accessToken on every xxl-job-admin instance bundled with Skyeye — do not leave it at the empty default
  • Restrict network access to the xxl-job-admin web UI and API to trusted internal management networks; never expose it directly to the internet
  • Block or firewall the default executor port (9999) and the admin API from untrusted sources
  • Upgrade Skyeye/its bundled xxl-job-admin to a release that includes the fix landed after commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321, or apply the equivalent authentication check to the affected JobInfoController routes if self-patching
  • Disable GLUE script job types (GLUE_SHELL, GLUE_PYTHON, GLUE_POWERSHELL, Groovy, PHP, Node.js) entirely if this functionality is not actively required

Detection Opportunities

  • Review xxl-job-admin access logs for unauthenticated or token-less requests to /jobinfo/addJob, /jobinfo/addAndStart, /jobinfo/removeJob, or /jobinfo/startJob
  • Audit existing job definitions for unexpected GLUE_SHELL/GLUE_PYTHON/GLUE_POWERSHELL jobs, especially ones not created through normal change-management processes
  • Monitor executor hosts for anomalous child processes spawned by the xxl-job executor runtime
  • Alert on job creation or deletion activity that does not correlate with an authenticated admin session

Defence-in-Depth

  • Place xxl-job-admin and its executors on an isolated management network segment, reachable only from authorized administrative hosts
  • Apply least-privilege service accounts to the executor process so a compromised job cannot reach sensitive systems directly
  • Treat any bundled or vendored third-party admin console (like xxl-job-admin inside Skyeye) as part of your attack surface and include it in routine vulnerability scanning, not just the primary application

Discovery & Disclosure

  • Published: 2026-10-08 (NVD)
  • CISA KEV Status: Not yet listed as of this writing
  • Proof-of-Concept: No public, automated exploit tool has been confirmed; the disclosure (Dromara Skyeye GitHub issue #29) documents the manual unauthenticated request needed to reproduce the issue
  • Context: This flaw was disclosed alongside other pre-authentication critical issues reported against Skyeye in the same report, including unrelated TTS and OnlyOffice-integration vulnerabilities — this advisory covers only the xxl-job-admin unauthenticated job-control issue tracked as CVE-2026-107779

References