← Back

CVE-2026-26718

nvd nist
Published: Jul 15, 2026Modified: Jul 16, 2026Deferred

JSON object

Loading...
9.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Exploitability: 3.9 / Impact: 5.2
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

A Cross-Site Request Forgery (CSRF) vulnerability exists in the xxl-job-admin web application v.3.0.0 that allows an attacker to perform unauthorized modifications to Glue IDE shell scripts. The affected endpoint lacks proper CSRF token validation and accepts arbitrary HTTP methods via a permissive request mapping

References (3)

Source: cve@mitre.org
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0

Timeline

No history available yet.