{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/skyeye--003549ae5615bd114ba5bb8ddf6a8e8ead97c321/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:dromara:skyeye:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-107779"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Skyeye (\u003c= 003549ae5615bd114ba5bb8ddf6a8e8ead97c321)"],"_cs_severities":["critical"],"_cs_tags":["remote-code-execution","web-application-security"],"_cs_type":"advisory","_cs_vendors":["Dromara"],"content_html":"\u003cp\u003eDromara Skyeye, up to and including commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321, is vulnerable to a critical missing authentication vulnerability (CVE-2026-107779). The vulnerability exists within the bundled xxl-job-admin JobInfoController endpoints, specifically those annotated with @PermissionLimit(limit = false). This flaw allows unauthenticated remote attackers to interact with the /jobinfo/addAndStart endpoint. By submitting crafted job payloads, an attacker can specify GLUE_SHELL, GLUE_PYTHON, or GLUE_POWERSHELL job types with arbitrary glueSource code. This effectively grants the attacker the ability to execute unauthorized commands, stop jobs, or delete jobs directly on the underlying executor host. Given the severity of the remote code execution (RCE) vector and the ease of exploitation, this vulnerability poses a significant threat to any infrastructure deploying the affected version of Skyeye.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in full remote code execution on the executor host. Attackers can leverage this access to perform lateral movement, data exfiltration, or complete system compromise. Any environment utilizing the affected Dromara Skyeye build is at high risk of unauthorized command execution.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately restrict network access to the Dromara Skyeye management interface, ensuring it is not exposed to the public internet.\u003c/li\u003e\n\u003cli\u003eAudit web server logs for HTTP POST requests targeting /jobinfo/addAndStart from unauthorized source IP addresses.\u003c/li\u003e\n\u003cli\u003eMonitor for suspicious child processes spawned by the Java process hosting the xxl-job-admin component, specifically looking for shell execution (cmd.exe, /bin/sh, /bin/bash) or script interpreter invocations (python, powershell.exe).\u003c/li\u003e\n\u003cli\u003eUpdate Dromara Skyeye to a version beyond commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 as soon as a patch is released by the maintainers.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-08T22:02:57Z","date_published":"2026-10-08T22:02:57Z","id":"https://feed.craftedsignal.io/briefs/2026-10-dromara-skyeye-rce/","summary":"Dromara Skyeye contains a missing authentication vulnerability in its bundled xxl-job-admin JobInfoController, allowing unauthenticated attackers to execute arbitrary shell, Python, or PowerShell jobs on the executor host.","title":"Unauthenticated Remote Code Execution in Dromara Skyeye","url":"https://feed.craftedsignal.io/briefs/2026-10-dromara-skyeye-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Skyeye (\u003c= 003549ae5615bd114ba5bb8ddf6a8e8ead97c321)","version":"https://jsonfeed.org/version/1.1"}