LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2026-26718

Published
CVSS9.1
Severitycritical
WeaknessCWE-352
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Description

A Cross-Site Request Forgery (CSRF) vulnerability exists in the xxl-job-admin web application v.3.0.0 that allows an attacker to perform unauthorized modifications to Glue IDE shell scripts. The affected endpoint lacks proper CSRF token validation and accepts arbitrary HTTP methods via a permissive request mapping

References

← Back to the CVE Tracker

Our coverage of CVE-2026-26718

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-26718.