Junglewise Threat Intelligence

CVE-2026-90488: Xuxueli xxl-job remote code execution in Groovy class loader

CVE-2026-90488 · Severity: medium · CVSS 6.3 · Published 2026-09-13

Technologies: Xuxueli XXL-JOB.

Executive brief

Xuxueli xxl-job is a distributed job scheduling framework used to automate task execution across systems. A code injection vulnerability in the Groovy class loader allows remote attackers to execute arbitrary code, enabling full system compromise including data theft, malware installation, and operational disruption.

Technical details

The vulnerability is a code injection flaw in the GroovyClassLoader.parseClass function within GlueFactory.java. An attacker can inject malicious Groovy code that gets parsed and executed during class loading, leading to remote code execution. The attack is network-accessible and does not require authentication. Exploitation has been publicly disclosed with proof-of-concept code available; the vendor has not responded to early disclosure notifications. A patch status is not explicitly confirmed in the advisory.

Affected products

  • Xuxueli xxl-job up to 3.4.2

Timeline

  • 2026-09-13: disclosed
  • other: Public proof-of-concept exploit available

References