Skip to content
Threat Feed
critical advisory

Unauthenticated Remote Code Execution in Dromara Skyeye

Dromara Skyeye contains a missing authentication vulnerability in its bundled xxl-job-admin JobInfoController, allowing unauthenticated attackers to execute arbitrary shell, Python, or PowerShell jobs on the executor host.

CVE search metadata

CVE search record: CVE-2026-107779. Severity: critical. CVSS: 9.8. KEV: no. Product: Skyeye (<= 003549ae5615bd114ba5bb8ddf6a8e8ead97c321). Brief: Unauthenticated Remote Code Execution in Dromara Skyeye. Brief link: https://feed.craftedsignal.io/briefs/2026-10-dromara-skyeye-rce/

Dromara Skyeye, up to and including commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321, is vulnerable to a critical missing authentication vulnerability (CVE-2026-107779). The vulnerability exists within the bundled xxl-job-admin JobInfoController endpoints, specifically those annotated with @PermissionLimit(limit = false). This flaw allows unauthenticated remote attackers to interact with the /jobinfo/addAndStart endpoint. By submitting crafted job payloads, an attacker can specify GLUE_SHELL, GLUE_PYTHON, or GLUE_POWERSHELL job types with arbitrary glueSource code. This effectively grants the attacker the ability to execute unauthorized commands, stop jobs, or delete jobs directly on the underlying executor host. Given the severity of the remote code execution (RCE) vector and the ease of exploitation, this vulnerability poses a significant threat to any infrastructure deploying the affected version of Skyeye.

Impact

Successful exploitation results in full remote code execution on the executor host. Attackers can leverage this access to perform lateral movement, data exfiltration, or complete system compromise. Any environment utilizing the affected Dromara Skyeye build is at high risk of unauthorized command execution.

Recommendation

  • Immediately restrict network access to the Dromara Skyeye management interface, ensuring it is not exposed to the public internet.
  • Audit web server logs for HTTP POST requests targeting /jobinfo/addAndStart from unauthorized source IP addresses.
  • Monitor for suspicious child processes spawned by the Java process hosting the xxl-job-admin component, specifically looking for shell execution (cmd.exe, /bin/sh, /bin/bash) or script interpreter invocations (python, powershell.exe).
  • Update Dromara Skyeye to a version beyond commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 as soon as a patch is released by the maintainers.

Immediate actions

Deploy web server rule to monitor /jobinfo/addAndStart

Detection Engineering 24h

Mitigations

Isolate Skyeye management interfaces from external access

immediate IT Operations

CVE-2026-107779

Detection coverage 1

Detect CVE-2026-107779 Exploitation - Unauthorized Job Submission

critical

Detects unauthenticated POST requests to the /jobinfo/addAndStart endpoint associated with Skyeye job execution exploitation.

sigma tactics: initial_access techniques: T1190 sources: webserver

Detection queries are available on the platform. Get full rules →