CVE-2026-90488 | Xuxueli xxl-job up to 3.4.2 GlueFactory.java GroovyClassLoader.parseClass code injection

SecurityVulns

A vulnerability, which was classified as critical, has been found in Xuxueli xxl-job up to 3.4.2. This affects the function GroovyClassLoader.parseClass of the file xxl-job-core/src/main/java/com/xxl/job/core/glue/GlueFactory.java. This manipulation causes code injection.

This vulnerability is registered as CVE-2026-90488. Remote exploitation of the attack is possible. Furthermore, an exploit is available.

The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More