MEDIUMVulnerability

CVE-2026-90488

A vulnerability was determined in Xuxueli xxl-job up to 3.4.2. This affects the function GroovyClassLoader.parseClass of the file xxl-job-core/src/main/java/com/xxl/job/core/glue/GlueFactory.java. This manipulation causes code injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

Properties

severity
MEDIUM
score
6.3
cve_id
CVE-2026-90488
signal_observed_at
2026-09-21T23:07:07+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
published_at
2026-09-13T00:17:06.680
last_modified
2026-09-15T15:17:27.203

Related Entities (3)

HAS_WEAKNESS (2)

[Weakness]Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
[Weakness]Improper Control of Generation of Code ('Code Injection')

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-90488 — Ninja Signal Threat Intelligence | Ninja Signal