VYPR
Critical severity9.8NVD Advisory· Published Oct 8, 2026· Updated Oct 8, 2026

CVE-2026-107779

CVE-2026-107779

Description

Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 contains a missing authentication vulnerability in bundled xxl-job-admin JobInfoController endpoints annotated with @PermissionLimit(limit = false). Unauthenticated attackers can POST GLUE_SHELL, GLUE_PYTHON, or GLUE_POWERSHELL jobs with attacker-supplied glueSource to /jobinfo/addAndStart, executing commands on the executor host or stopping and deleting jobs.

Affected products

1
  • Dromara/skyeyellm-fuzzy
    Range: through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.