A vulnerability was determined in xuxueli xxl-job up to 3.5.0. The impacted element is an unknown function of the file /jobgroup/insert. This manipulation of the argument Name causes cross site scripting. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early this disclosure but did not respond in any way.
Modify values to recalculate the CVSS score in real-time
Exploit Prediction Scoring System (EPSS)
0.19% probability of exploitation in the 30 days.
Higher than 9% of all CVEs
References & External Links
Community & Discussion
Critical Vulnerabilities — Last 7 Days
Real-time tracking of CVSS 9.0+ remote execution zero-days, public exploit code, and ransomware-linked vulnerabilities disclosed this week.
Frequently Asked Questions
CVE-2026-94426 is a Low severity security vulnerability. A vulnerability was determined in xuxueli xxl-job up to 3.5.0. The impacted element is an unknown function of the file /jobgroup/insert. This manipulation of the...
This vulnerability has a CVSS score of 3.5 out of 10, rated as Low. Low severity vulnerabilities have limited impact and typically require local access or authenticated sessions to exploit.
To protect against CVE-2026-94426, you should: (1) Apply the latest security patches from the vendor, (2) Check official security advisories for specific remediation steps, (3) Update affected software to the latest version, and (4) Monitor your systems for any signs of exploitation.
This vulnerability was publicly disclosed on September 21, 2026. Organizations should check if they were vulnerable during the period before the patch was available.
No public exploit code has been confirmed for CVE-2026-94426 at this time. Security teams should monitor threat feeds for emerging developments and apply vendor patches proactively.
Currently, CVE-2026-94426 is not recorded in the CISA Known Exploited Vulnerabilities (KEV) catalog as being actively exploited in the wild. Security teams should still patch proactively to prevent zero-day targeting.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
