Unrated severityNVD Advisory· Published Jul 15, 2026· Updated Jul 16, 2026
CVE-2026-26718
CVE-2026-26718
Description
A Cross-Site Request Forgery (CSRF) vulnerability exists in the xxl-job-admin web application v.3.0.0 that allows an attacker to perform unauthorized modifications to Glue IDE shell scripts. The affected endpoint lacks proper CSRF token validation and accepts arbitrary HTTP methods via a permissive request mapping
Affected products
1- Range: =3.0.0
Patches
Vulnerability mechanics
References
1- xxl-job-admin.commitre
News mentions
0No linked articles in our index yet.