Junglewise Threat Intelligence

CVE-2026-90487: Xuxueli xxl-job privilege escalation in JobGroupController

CVE-2026-90487 · Severity: medium · CVSS 4.3 · Published 2026-09-12

Technologies: Xuxueli XXL-JOB.

Executive brief

xxl-job is a distributed task scheduling framework used by organizations to manage and execute automated jobs across multiple servers. This vulnerability in the job group management controller allows attackers to escalate privileges and manipulate job group configurations without proper authorization, potentially enabling unauthorized job creation, modification, or deletion across the entire scheduling infrastructure.

Technical details

An improper privilege management vulnerability exists in the JobGroupController.java file of xxl-job up to version 3.4.2, specifically in endpoint authentication handling. The loadById endpoint is missing authentication checks, allowing unauthenticated remote attackers to access and potentially modify job group configurations. The vulnerability enables attackers to bypass authorization controls and perform administrative operations on job groups without valid credentials. The exploit code has been publicly disclosed, though the vendor has not responded to early vulnerability notifications. A patch status is not yet available.

Affected products

  • Xuxueli xxl-job up to 3.4.2

Timeline

  • 2026-09-12: disclosed

References