Skip to content
CVE-2026-94426 - Low Vulnerability

CVE-2026-94426 - Low Vulnerability

Thehackerwire • September 22, 2026

A vulnerability was determined in xuxueli xxl-job up to 3.5.0. The impacted element is an unknown function of the file /jobgroup/insert. This manipulation of the argument Name causes cross site scripting. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early this disclosure but did not respond in any way.

Modify values to recalculate the CVSS score in real-time

Exploit Prediction Scoring System (EPSS)

0.19% probability of exploitation in the 30 days.

Higher than 9% of all CVEs

References & External Links

Community & Discussion

Critical Vulnerabilities — Last 7 Days

Real-time tracking of CVSS 9.0+ remote execution zero-days, public exploit code, and ransomware-linked vulnerabilities disclosed this week.

Frequently Asked Questions

CVE-2026-94426 is a Low severity security vulnerability. A vulnerability was determined in xuxueli xxl-job up to 3.5.0. The impacted element is an unknown function of the file /jobgroup/insert. This manipulation of the...

This vulnerability has a CVSS score of 3.5 out of 10, rated as Low. Low severity vulnerabilities have limited impact and typically require local access or authenticated sessions to exploit.

To protect against CVE-2026-94426, you should: (1) Apply the latest security patches from the vendor, (2) Check official security advisories for specific remediation steps, (3) Update affected software to the latest version, and (4) Monitor your systems for any signs of exploitation.

This vulnerability was publicly disclosed on September 21, 2026. Organizations should check if they were vulnerable during the period before the patch was available.

No public exploit code has been confirmed for CVE-2026-94426 at this time. Security teams should monitor threat feeds for emerging developments and apply vendor patches proactively.

Currently, CVE-2026-94426 is not recorded in the CISA Known Exploited Vulnerabilities (KEV) catalog as being actively exploited in the wild. Security teams should still patch proactively to prevent zero-day targeting.

Extracted Entities

Vulnerabilities (1)