A Cross-Site Request Forgery (CSRF) vulnerability exists in the xxl-job-admin web application v.3.0.0 that allows an attacker to perform unauthorized modifications to Glue IDE shell scripts. The affected endpoint lacks proper CSRF token validation and accepts arbitrary HTTP methods via a permissive request mapping
References
Configurations
No configuration.
History
16 Jul 2026, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/Ibrahim-Sartawi/CVE-2026-26718 - | |
| CWE | CWE-352 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.1 |
15 Jul 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-15 22:16
Updated : 2026-07-16 19:16
NVD link : CVE-2026-26718
Mitre link : CVE-2026-26718
CVE.ORG link : CVE-2026-26718
JSON object : View
Products Affected
No product.
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
