Executive brief
XXL-JOB, a distributed task scheduling framework, contains a security flaw where it ships with a default, publicly known access token. This allows remote attackers to bypass authentication on management interfaces if the default settings are not changed by the administrator. An attacker could use this access to interfere with scheduled tasks, register unauthorized endpoints, or disrupt legitimate operations.
Technical details
A use of hard-coded cryptographic key (CWE-321) exists in the OpenAPI endpoint of XXL-JOB up to version 3.3.2. The OpenApiController.java component relies on the 'XXL-JOB-ACCESS-TOKEN' header for authorization but defaults to a publicly known value ('default_token'). Because the OpenAPI entrypoint explicitly disables SSO login, an unauthenticated remote attacker can use this default token to invoke privileged operations such as executor registration, registry removal, and task callbacks. While the attack is remote, it is classified as high complexity because it requires the target deployment to have retained the default configuration.
Affected products
- Xuxueli xxl-job up to 3.3.2
Timeline
- 2026-03-25: disclosed: Issue reported on GitHub repository
- 2026-04-28: advisory: NVD publication date