PatchSiren cyber security CVE debrief
CVE-2026-7306 Xuxueli CVE debrief
A security vulnerability has been detected in Xuxueli xxl-job up to 3.3.2. The impacted element is an unknown function of the file xxl-job-admin/src/main/java/com/xxl/job/admin/scheduler/openapi/OpenApiController.java of the component OpenAPI Endpoint. Such manipulation of the argument default_token leads to use of hard-coded cryptographic key. It is possible to launch the attack remotely. A high complexity level is associated with this attack. The exploitability is regarded as difficult. The vulnerability has been publicly disclosed.
- Vendor
- Xuxueli
- Product
- xxl-job
- CVSS
- LOW 2.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-28
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-28
- Advisory updated
- 2026-07-24
Who should care
Users of Xuxueli xxl-job up to version 3.3.2 should be aware of this vulnerability and take necessary precautions to protect their deployments. This includes reviewing the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
Technical summary
The vulnerability is located in the OpenAPI Endpoint of the xxl-job-admin component, specifically in the OpenApiController.java file. The manipulation of the default_token argument leads to the use of a hard-coded cryptographic key. This vulnerability can be exploited remotely with high complexity and difficult exploitability, potentially impacting users of Xuxueli xxl-job up to version 3.3.2. Affected product deployments should be reviewed for exposure, and compensating controls may be necessary until remediation is applied. Evidence is based on limited source information and may change as new details emerge. Users should verify affected scope, severity, and vendor guidance through official advisories or CVE records.
Defensive priority
Medium
Recommended defensive actions
- Inventory and verify affected versions of Xuxueli xxl-job
- Apply vendor remediation or patches when available
- Implement compensating controls to mitigate potential attacks
- Monitor for suspicious activity related to the OpenAPI Endpoint
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record was published on 2026-04-28T22:16:51.060Z and was last modified on 2026-07-24T08:10:00.150Z. The NVD entry is currently Deferred. The vulnerability has been detected in Xuxueli xxl-job up to version 3.3.2. Evidence is based on limited source information and may change as new details emerge.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-7306 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-7306
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-7306 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-7306
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/xuxueli/xxl-job/
-
Source reference
Unverified legacy reference
URL: https://github.com/xuxueli/xxl-job/issues/3938
-
Source reference
Unverified legacy reference
URL: https://github.com/xuxueli/xxl-job/issues/3938
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/submit/803077
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/359961
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/359961/cti
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.