<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Skyeye (&lt;= 003549ae5615bd114ba5bb8ddf6a8e8ead97c321) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/skyeye--003549ae5615bd114ba5bb8ddf6a8e8ead97c321/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 08 Oct 2026 22:02:57 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/skyeye--003549ae5615bd114ba5bb8ddf6a8e8ead97c321/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Unauthenticated Remote Code Execution in Dromara Skyeye</title><link>https://feed.craftedsignal.io/briefs/2026-10-dromara-skyeye-rce/</link><pubDate>Thu, 08 Oct 2026 22:02:57 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-dromara-skyeye-rce/</guid><description>Dromara Skyeye contains a missing authentication vulnerability in its bundled xxl-job-admin JobInfoController, allowing unauthenticated attackers to execute arbitrary shell, Python, or PowerShell jobs on the executor host.</description><content:encoded><![CDATA[<p>Dromara Skyeye, up to and including commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321, is vulnerable to a critical missing authentication vulnerability (CVE-2026-107779). The vulnerability exists within the bundled xxl-job-admin JobInfoController endpoints, specifically those annotated with @PermissionLimit(limit = false). This flaw allows unauthenticated remote attackers to interact with the /jobinfo/addAndStart endpoint. By submitting crafted job payloads, an attacker can specify GLUE_SHELL, GLUE_PYTHON, or GLUE_POWERSHELL job types with arbitrary glueSource code. This effectively grants the attacker the ability to execute unauthorized commands, stop jobs, or delete jobs directly on the underlying executor host. Given the severity of the remote code execution (RCE) vector and the ease of exploitation, this vulnerability poses a significant threat to any infrastructure deploying the affected version of Skyeye.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in full remote code execution on the executor host. Attackers can leverage this access to perform lateral movement, data exfiltration, or complete system compromise. Any environment utilizing the affected Dromara Skyeye build is at high risk of unauthorized command execution.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Immediately restrict network access to the Dromara Skyeye management interface, ensuring it is not exposed to the public internet.</li>
<li>Audit web server logs for HTTP POST requests targeting /jobinfo/addAndStart from unauthorized source IP addresses.</li>
<li>Monitor for suspicious child processes spawned by the Java process hosting the xxl-job-admin component, specifically looking for shell execution (cmd.exe, /bin/sh, /bin/bash) or script interpreter invocations (python, powershell.exe).</li>
<li>Update Dromara Skyeye to a version beyond commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 as soon as a patch is released by the maintainers.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>remote-code-execution</category><category>web-application-security</category></item></channel></rss>