Mmastodon TechnologyCybersecurity first seen 9 h ago, last 9 h ago, peak #7
Two critical unpatched flaws hit Dromara Skyeye
Original: 🔴 Dromara Skyeye — 2× CVSS 9.8, no patch, PoC public CVE-2026-107779 — missing auth in xxl-job-admin (CWE-306) → /jobinf
Security researchers are warning about two vulnerabilities in Dromara Skyeye, both rated CVSS 9.8 and currently unpatched. One flaw, CVE-2026-107779, stems from missing authentication in the bundled xxl-job-admin component, letting attackers start GLUE_SHELL jobs and achieve remote code execution on executor hosts. The second, CVE-2026-107780, is an OS command injection in a TTS endpoint. A public proof-of-concept exploit exists, raising fears of widespread exploitation before fixes arrive.
Why now: Publicly available exploit code and critical severity with no patch make these flaws an urgent concern for defenders.
Dromara Skyeyexxl-job-adminCVE-2026-107779CVE-2026-107780
Evidence
- 🔴 Dromara Skyeye — 2× CVSS 9.8, no patch, PoC public CVE-2026-107779 — missing auth in xxl-job-admin (CWE-306) → /jobinfo/addAndStart accepts GLUE_SHELL jobs unauthenticated → RCE on executor host CVE-2026-107780 — OS command injection in TTS endpoint (CWE-78) →… · threataft@infosec.exchange · 3
API: https://socialmediatrends-api.osmike.com/v1/trends/1613621