PT-2026-35826 · Xuxueli · Xxl-Job

Larlarua

·

Published

2026-04-28

·

Updated

2026-04-28

·

CVE-2026-7306

CVSS v3.1

5.6

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Xuxueli xxl-job versions prior to 3.3.3
Description An issue exists in the OpenAPI Endpoint within the file xxl-job-admin/src/main/java/com/xxl/job/admin/scheduler/openapi/OpenApiController.java. Manipulation of the default token argument leads to the use of a hard-coded cryptographic key. This flaw allows for remote attacks, although it is characterized by high complexity and difficult exploitability.
Recommendations Update to a version newer than 3.3.2. As a temporary workaround, restrict access to the default token argument in the OpenAPI Endpoint to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-7306

Affected Products

Xxl-Job