A Cross-Site Request Forgery (CSRF) vulnerability exists in the xxl-job-admin web application v.3.0.0 that allows an attacker to perform unauthorized modifications to Glue IDE shell scripts. The affected endpoint lacks proper CSRF token validation and accepts arbitrary HTTP methods via a permissive request mapping
Metrics
Affected Vendors & Products
References
History
Mon, 03 Aug 2026 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | CSRF Vulnerability in xxl‑job‑admin 3.0.0 Enables Unauthorized Modification of Glue IDE Scripts |
Tue, 28 Jul 2026 04:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | CSRF Vulnerability in xxl‑job‑admin 3.0.0 Enables Unauthorized Modification of Glue IDE Scripts |
Wed, 22 Jul 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Cross‑Site Request Forgery Enables Unauthorized Glue IDE Shell Script Modification in xxl‑job‑admin 3.0.0 |
Fri, 17 Jul 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Cross‑Site Request Forgery Enables Unauthorized Glue IDE Shell Script Modification in xxl‑job‑admin 3.0.0 |
Thu, 16 Jul 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-352 | |
| Metrics |
cvssV3_1
|
Wed, 15 Jul 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Cross-Site Request Forgery (CSRF) vulnerability exists in the xxl-job-admin web application v.3.0.0 that allows an attacker to perform unauthorized modifications to Glue IDE shell scripts. The affected endpoint lacks proper CSRF token validation and accepts arbitrary HTTP methods via a permissive request mapping | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2026-07-15T00:00:00.000Z
Updated: 2026-07-16T18:28:28.231Z
Reserved: 2026-02-16T00:00:00.000Z
Link: CVE-2026-26718
Updated: 2026-07-16T18:28:24.225Z
No data.
No data.