PT-2026-35824 · Xuxueli · Xxl-Job

Larlarua

·

Published

2026-04-28

·

Updated

2026-04-29

·

CVE-2026-7303

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Xuxueli xxl-job versions prior to 3.4.0
Description A security flaw exists in the Execution Log Handler component within the logDetailCat() function of the JobLogController.java file. Remote manipulation of the logId argument leads to improper control of resource identifiers. This issue is characterized by high complexity and difficult exploitability.
Recommendations Upgrade to version 3.4.0. As a temporary workaround, restrict access to the logDetailCat() function to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-7303
GHSA-GW2X-MFWR-H46P

Affected Products

Xxl-Job