Description
A security vulnerability has been detected in Xuxueli xxl-job up to 3.3.2. The impacted element is an unknown function of the file xxl-job-admin/src/main/java/com/xxl/job/admin/scheduler/openapi/OpenApiController.java of the component OpenAPI Endpoint. Such manipulation of the argument default_token leads to use of hard-coded cryptographic key . It is possible to launch the attack remotely. A high complexity level is associated with this attack. The exploitability is regarded as difficult. The exploit has been disclosed publicly and may be used.
Problem types
Use of Hard-coded Cryptographic Key
Product status
3.3.1
3.3.2
Timeline
| 2026-04-28: | Advisory disclosed |
| 2026-04-28: | VulDB entry created |
| 2026-04-28: | VulDB entry last update |
Credits
larlarua (VulDB User)
References
vuldb.com/vuln/359961 (VDB-359961 | Xuxueli xxl-job OpenAPI Endpoint OpenApiController.java hard-coded key)
vuldb.com/vuln/359961/cti (VDB-359961 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/submit/803077 (Submit #803077 | xuxueli https://github.com/xuxueli/xxl-job v3.3.2 Authorization Bypass)
github.com/xuxueli/xxl-job/issues/3938
github.com/xuxueli/xxl-job/issues/3938
github.com/xuxueli/xxl-job/