Unauthenticated Remote Code Execution in Dromara Skyeye
Dromara Skyeye contains a missing authentication vulnerability in its bundled xxl-job-admin JobInfoController, allowing unauthenticated attackers to execute arbitrary shell, Python, or PowerShell jobs on the executor host.
CVE search metadata
CVE search record: CVE-2026-107779. Severity: critical. CVSS: 9.8. KEV: no. Product: Skyeye (<= 003549ae5615bd114ba5bb8ddf6a8e8ead97c321). Brief: Unauthenticated Remote Code Execution in Dromara Skyeye. Brief link: https://feed.craftedsignal.io/briefs/2026-10-dromara-skyeye-rce/
Dromara Skyeye, up to and including commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321, is vulnerable to a critical missing authentication vulnerability (CVE-2026-107779). The vulnerability exists within the bundled xxl-job-admin JobInfoController endpoints, specifically those annotated with @PermissionLimit(limit = false). This flaw allows unauthenticated remote attackers to interact with the /jobinfo/addAndStart endpoint. By submitting crafted job payloads, an attacker can specify GLUE_SHELL, GLUE_PYTHON, or GLUE_POWERSHELL job types with arbitrary glueSource code. This effectively grants the attacker the ability to execute unauthorized commands, stop jobs, or delete jobs directly on the underlying executor host. Given the severity of the remote code execution (RCE) vector and the ease of exploitation, this vulnerability poses a significant threat to any infrastructure deploying the affected version of Skyeye.
Impact
Successful exploitation results in full remote code execution on the executor host. Attackers can leverage this access to perform lateral movement, data exfiltration, or complete system compromise. Any environment utilizing the affected Dromara Skyeye build is at high risk of unauthorized command execution.
Recommendation
- Immediately restrict network access to the Dromara Skyeye management interface, ensuring it is not exposed to the public internet.
- Audit web server logs for HTTP POST requests targeting /jobinfo/addAndStart from unauthorized source IP addresses.
- Monitor for suspicious child processes spawned by the Java process hosting the xxl-job-admin component, specifically looking for shell execution (cmd.exe, /bin/sh, /bin/bash) or script interpreter invocations (python, powershell.exe).
- Update Dromara Skyeye to a version beyond commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 as soon as a patch is released by the maintainers.
Immediate actions
Deploy web server rule to monitor /jobinfo/addAndStart
Mitigations
Isolate Skyeye management interfaces from external access
CVE-2026-107779
Detection coverage 1
Detect CVE-2026-107779 Exploitation - Unauthorized Job Submission
criticalDetects unauthenticated POST requests to the /jobinfo/addAndStart endpoint associated with Skyeye job execution exploitation.
Detection queries are available on the platform. Get full rules →