CVE-2026-26718
48Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 9.1epss 0.2%
from disclosure to weapon0 days
Published on NVDJul 15
1st PoCJul 14
exploitation probability
0.2%top 87% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
A Cross-Site Request Forgery (CSRF) vulnerability exists in the xxl-job-admin web application v.3.0.0 that allows an attacker to perform unauthorized modifications to Glue IDE shell scripts. The affected endpoint lacks proper CSRF token validation and accepts arbitrary HTTP methods via a permissive request mapping
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected products
n/a · n/apublic PoCs found — 1
githubgithub.com/Ibrahim-Sartawi/CVE-2026-26718★ 1⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.