A Cross-Site Request Forgery (CSRF) vulnerability exists in the xxl-job-admin web application v.3.0.0 that allows an attacker to perform unauthorized modifications to Glue IDE shell scripts. The affected endpoint lacks proper CSRF token validation and accepts arbitrary HTTP methods via a permissive request mapping
History

Mon, 03 Aug 2026 03:30:00 +0000

Type Values Removed Values Added
Title CSRF Vulnerability in xxl‑job‑admin 3.0.0 Enables Unauthorized Modification of Glue IDE Scripts

Tue, 28 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title CSRF Vulnerability in xxl‑job‑admin 3.0.0 Enables Unauthorized Modification of Glue IDE Scripts

Wed, 22 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Cross‑Site Request Forgery Enables Unauthorized Glue IDE Shell Script Modification in xxl‑job‑admin 3.0.0

Fri, 17 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Title Cross‑Site Request Forgery Enables Unauthorized Glue IDE Shell Script Modification in xxl‑job‑admin 3.0.0

Thu, 16 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-352
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 15 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Description A Cross-Site Request Forgery (CSRF) vulnerability exists in the xxl-job-admin web application v.3.0.0 that allows an attacker to perform unauthorized modifications to Glue IDE shell scripts. The affected endpoint lacks proper CSRF token validation and accepts arbitrary HTTP methods via a permissive request mapping
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2026-07-15T00:00:00.000Z

Updated: 2026-07-16T18:28:28.231Z

Reserved: 2026-02-16T00:00:00.000Z

Link: CVE-2026-26718

cve-icon Vulnrichment

Updated: 2026-07-16T18:28:24.225Z

cve-icon NVD

No data.

cve-icon Redhat

No data.