CVE-2026-7303 Details
Description
A security flaw has been discovered in Xuxueli xxl-job up to 3.3.2. Impacted is the function logDetailCat of the file xxl-job-admin/src/main/java/com/xxl/job/admin/controller/biz/JobLogController.java of the component Execution Log Handler. The manipulation of the argument logId results in improper control of resource identifiers. The attack may be performed from remote. This attack is characterized by high complexity. The exploitability is considered difficult. The exploit has been released to the public and may be used for attacks. Upgrading to version 3.4.0 is recommended to address this issue. The patch is identified as d24e4ccd6073cc75305e1d3b9c29bc8db7437e7a. It is suggested to upgrade the affected component.
A vulnerability allowing unauthorized access to execution logs has been identified in XXL-Job versions through 3.3.2. The issue arises in the 'logDetailCat' function of the 'JobLogController' component, where the 'logId' parameter is not properly validated against job group permissions. This flaw enables authenticated users to access log details from job groups they do not have authorization for, potentially exposing sensitive information such as business parameters, internal network addresses, stack traces, and secrets logged by jobs during execution.
Users are advised to upgrade to XXL-Job version 3.4.0, where this vulnerability has been addressed. After upgrading, ensure that the 'logDetailCat' function properly checks job group permissions before returning log details.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 28, 2026CISA-ADP
Assessed Apr 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/xuxueli/xxl-job/ | [email protected] | ProductSource CodeVendor |
| https://github.com/xuxueli/xxl-job/commit/d24e4ccd6073cc75305e1d3b9c29bc8db7437e7a | [email protected] | Source CodeVendor |
| https://github.com/xuxueli/xxl-job/issues/3936 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/xuxueli/xxl-job/releases/tag/v3.4.0 | [email protected] | Release NotesVendor |
| https://vuldb.com/submit/803075 | [email protected] | Permission Required |
| https://vuldb.com/vuln/359959 | [email protected] | AdvisoryPermission RequiredRemedy |
| https://vuldb.com/vuln/359959/cti | [email protected] | AdvisoryPermission Required |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-99 | Improper Control of Resource Identifiers ('Resource Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Xuxueli xxl-job | <= 3.3.2 (semver) |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Apr 28, 2026 | New CVE Received | [email protected] |
Volerion