Overview
CVE-2026-107779 is a critical missing-authentication vulnerability (CVSS 9.8) in Dromara Skyeye, affecting the xxl-job-admin component it bundles for distributed task scheduling. Several endpoints in JobInfoController — including /jobinfo/addJob, /jobinfo/addAndStart, /jobinfo/removeJob, and /jobinfo/startJob — are annotated @PermissionLimit(limit = false), which skips the application's normal authentication checks entirely. Because xxl-job's "GLUE" feature lets an admin define a job's business logic as raw script content (shell, Python, PowerShell, Groovy, PHP, or Node.js) stored and executed directly by the scheduler, an unauthenticated attacker who can reach these endpoints can submit a job with attacker-controlled script content and have it executed on the job executor host — resulting in remote code execution with no credentials and no user interaction required.
Technical Details
| Field | Value |
|---|---|
| CVE ID | CVE-2026-107779 |
| Severity | Critical (CVSS 3.1: 9.8, CVSS 4.0: 9.3) |
| Attack Vector | Network |
| Attack Complexity | Low |
| Authentication | None |
| User Interaction | None |
| Scope | Unchanged |
| Impact | Confidentiality: High, Integrity: High, Availability: High (arbitrary code execution on the job executor host) |
| Affected Versions | Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 (bundled xxl-job-admin 2.3.0) |
| Assigned By | VulnCheck |
| Disclosed | 2026-10-08 |
How It Works
The @PermissionLimit(limit = false) Bypass
xxl-job-admin's JobInfoController uses a @PermissionLimit annotation to mark which routes require an authenticated admin session. Several job-management endpoints — addJob, addAndStart, removeJob, and startJob — are marked @PermissionLimit(limit = false), which was apparently intended to exempt specific, low-risk routes from the check under controlled circumstances. In Skyeye's bundled copy of xxl-job-admin, that exemption instead applies to endpoints that create, start, and delete job definitions — core administrative functions that should never be reachable without a session.
Combined with xxl-job's commonly-deployed default of an empty xxl.job.accessToken, this means the job-management API is effectively open to anyone who can reach it over the network, with no login and no token required.
Abusing GLUE Jobs for Code Execution
xxl-job's "GLUE" mode lets a job's logic be submitted as raw source code (glueSource) in a chosen language (glueType), rather than compiled Java packaged with the executor. Supported glueType values reported in the disclosure include GLUE_SHELL, GLUE_PYTHON, GLUE_POWERSHELL, GROOVY, PHP, and NODEJS. Because the admin server trusts whatever script content is supplied and hands it to the executor to run, an attacker who can POST a job definition can embed arbitrary shell, Python, or PowerShell commands directly in glueSource.
Publicly described proof-of-concept behavior: with the default empty xxl.job.accessToken, an unauthenticated POST /jobinfo/addAndStart request with glueType: GLUE_SHELL and glueSource: echo pwn creates and immediately runs the job, with the output visible in the xxl-job UI and the executor's logs — confirming command execution on the executor host. The same primitive generalizes to any shell, Python, or PowerShell payload the attacker chooses, and the removeJob/startJob endpoints let the same unauthenticated actor also stop, delete, or re-trigger existing scheduled jobs.
Impact Assessment
| Impact Area | Description |
|---|---|
| Confidentiality | Full — arbitrary script execution can read any file or data accessible to the executor process |
| Integrity | Full — attacker-controlled jobs can modify application data, configuration, or deployed code |
| Availability | Full — the same unauthenticated endpoints can stop or delete legitimate scheduled jobs, disrupting dependent automation |
| Blast Radius | Any host running the bundled xxl-job executor that can reach the exposed admin API, plus anything that executor process can touch |
Who Is At Risk
- Any deployment of Dromara Skyeye (through the affected commit) with its bundled xxl-job-admin reachable from an untrusted network, including the public internet
- Installations that left
xxl.job.accessTokenat its empty/default value — the common case for this component - Organizations using Skyeye's job scheduler to run operational automation, since a compromised executor host can be a pivot point into adjacent infrastructure
Potential Attack Chain
- Discovery — Attacker identifies a reachable xxl-job-admin instance bundled with Skyeye, typically by scanning for the admin web UI or API paths on exposed hosts.
- Unauthenticated Access — Attacker sends requests directly to
/jobinfo/addAndStart(or the sibling endpoints) without any session cookie, API key, oraccessToken— the@PermissionLimit(limit = false)annotation lets the request through. - Malicious Job Submission — Attacker submits a job with
glueType: GLUE_SHELL(orGLUE_PYTHON/GLUE_POWERSHELL) and aglueSourcepayload containing arbitrary commands. - Remote Code Execution — The executor runs the submitted script, giving the attacker command execution with the privileges of the executor process.
- Post-Exploitation — The attacker can establish persistence via recurring jobs, exfiltrate data, pivot laterally, or use
removeJob/startJobto sabotage legitimate scheduled automation.
Mitigation
Immediate Actions
- Set a strong
xxl.job.accessTokenon every xxl-job-admin instance bundled with Skyeye — do not leave it at the empty default - Restrict network access to the xxl-job-admin web UI and API to trusted internal management networks; never expose it directly to the internet
- Block or firewall the default executor port (9999) and the admin API from untrusted sources
- Upgrade Skyeye/its bundled xxl-job-admin to a release that includes the fix landed after commit
003549ae5615bd114ba5bb8ddf6a8e8ead97c321, or apply the equivalent authentication check to the affectedJobInfoControllerroutes if self-patching - Disable GLUE script job types (
GLUE_SHELL,GLUE_PYTHON,GLUE_POWERSHELL, Groovy, PHP, Node.js) entirely if this functionality is not actively required
Detection Opportunities
- Review xxl-job-admin access logs for unauthenticated or token-less requests to
/jobinfo/addJob,/jobinfo/addAndStart,/jobinfo/removeJob, or/jobinfo/startJob - Audit existing job definitions for unexpected
GLUE_SHELL/GLUE_PYTHON/GLUE_POWERSHELLjobs, especially ones not created through normal change-management processes - Monitor executor hosts for anomalous child processes spawned by the xxl-job executor runtime
- Alert on job creation or deletion activity that does not correlate with an authenticated admin session
Defence-in-Depth
- Place xxl-job-admin and its executors on an isolated management network segment, reachable only from authorized administrative hosts
- Apply least-privilege service accounts to the executor process so a compromised job cannot reach sensitive systems directly
- Treat any bundled or vendored third-party admin console (like xxl-job-admin inside Skyeye) as part of your attack surface and include it in routine vulnerability scanning, not just the primary application
Discovery & Disclosure
- Published: 2026-10-08 (NVD)
- CISA KEV Status: Not yet listed as of this writing
- Proof-of-Concept: No public, automated exploit tool has been confirmed; the disclosure (Dromara Skyeye GitHub issue #29) documents the manual unauthenticated request needed to reproduce the issue
- Context: This flaw was disclosed alongside other pre-authentication critical issues reported against Skyeye in the same report, including unrelated TTS and OnlyOffice-integration vulnerabilities — this advisory covers only the xxl-job-admin unauthenticated job-control issue tracked as CVE-2026-107779