CVE-2026-107779
Deferred Deferred - Pending Action

Authentication Bypass in Dromara Skyeye JobInfoController

Vulnerability report for CVE-2026-107779, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: VulnCheck

Description

Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 contains a missing authentication vulnerability in bundled xxl-job-admin JobInfoController endpoints annotated with @PermissionLimit(limit = false). Unauthenticated attackers can POST GLUE_SHELL, GLUE_PYTHON, or GLUE_POWERSHELL jobs with attacker-supplied glueSource to /jobinfo/addAndStart, executing commands on the executor host or stopping and deleting jobs.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
dromara skyeye 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Dromara Skyeye has a missing authentication vulnerability in its xxl-job-admin JobInfoController endpoints. These endpoints are marked with @PermissionLimit(limit = false), allowing unauthenticated attackers to exploit them. Attackers can send POST requests to /jobinfo/addAndStart with malicious job commands like GLUE_SHELL, GLUE_PYTHON, or GLUE_POWERSHELL, enabling remote command execution on the executor host or unauthorized job management.

Detection Guidance

Check for unauthorized POST requests to /jobinfo/addAndStart with GLUE_SHELL, GLUE_PYTHON, or GLUE_POWERSHELL parameters. Inspect logs for suspicious job additions or executions on Dromara Skyeye systems.

Impact Analysis

This vulnerability allows attackers to execute arbitrary commands on the server hosting the Dromara Skyeye executor. They could take full control of the system, steal data, install malware, or disrupt services. Additionally, attackers can stop or delete existing jobs, potentially causing operational failures in systems relying on Skyeye for job scheduling.

Compliance Impact

This vulnerability likely violates compliance requirements for GDPR and HIPAA due to unauthorized access and potential data breaches. GDPR mandates strict access controls and breach notifications, while HIPAA requires safeguards against unauthorized system access. Exploitation could lead to unauthorized data exposure, triggering legal penalties and compliance violations.

Mitigation Strategies

Apply patches or updates to Dromara Skyeye to fix the missing authentication issue. Restrict network access to the xxl-job-admin endpoints. Monitor for unauthorized job submissions or executions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107779. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart