MEDIUMVulnerability
CVE-2026-90488
A vulnerability was determined in Xuxueli xxl-job up to 3.4.2. This affects the function GroovyClassLoader.parseClass of the file xxl-job-core/src/main/java/com/xxl/job/core/glue/GlueFactory.java. This manipulation causes code injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Properties
- severity
- MEDIUM
- score
- 6.3
- cve_id
- CVE-2026-90488
- signal_observed_at
- 2026-09-21T23:07:07+00:00
- vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
- published_at
- 2026-09-13T00:17:06.680
- last_modified
- 2026-09-15T15:17:27.203
Related Entities (3)
HAS_WEAKNESS (2)
→[Weakness]Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
→[Weakness]Improper Control of Generation of Code ('Code Injection')
DESCRIBED_BY (1)
→[Source]NVD
Explore deeper with Ninja Signal's threat intelligence graph