📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global phishing Cross-sector HIGH 3m Global data_breach Energy CRITICAL 1h Global phishing Government/Multi-sector HIGH 2h Global apt Education CRITICAL 4h Global vulnerability Enterprise Software / ERP Systems CRITICAL 5h Global vulnerability IT Infrastructure CRITICAL 6h Global vulnerability Technology and Software Development HIGH 7h Global vulnerability Enterprise IT and Government CRITICAL 7h Global ransomware Multiple Sectors / Enterprise CRITICAL 8h Global general Technology and Legal MEDIUM 8h Global phishing Cross-sector HIGH 3m Global data_breach Energy CRITICAL 1h Global phishing Government/Multi-sector HIGH 2h Global apt Education CRITICAL 4h Global vulnerability Enterprise Software / ERP Systems CRITICAL 5h Global vulnerability IT Infrastructure CRITICAL 6h Global vulnerability Technology and Software Development HIGH 7h Global vulnerability Enterprise IT and Government CRITICAL 7h Global ransomware Multiple Sectors / Enterprise CRITICAL 8h Global general Technology and Legal MEDIUM 8h Global phishing Cross-sector HIGH 3m Global data_breach Energy CRITICAL 1h Global phishing Government/Multi-sector HIGH 2h Global apt Education CRITICAL 4h Global vulnerability Enterprise Software / ERP Systems CRITICAL 5h Global vulnerability IT Infrastructure CRITICAL 6h Global vulnerability Technology and Software Development HIGH 7h Global vulnerability Enterprise IT and Government CRITICAL 7h Global ransomware Multiple Sectors / Enterprise CRITICAL 8h Global general Technology and Legal MEDIUM 8h
Vulnerabilities

CVE-2026-7305

Medium
CWE-918 — Weakness Type
Published: Apr 28, 2026  ·  Modified: May 1, 2026  ·  Source: NVD
CVSS v3
6.3
🔗 NVD Official
📄 Description (English)

A weakness has been identified in Xuxueli xxl-job up to 3.3.2. The affected element is the function triggerJob of the file xxl-job-admin/src/main/java/com/xxl/job/admin/service/impl/XxlJobServiceImpl.java of the component trigger Endpoint. This manipulation of the argument addressList causes server-side request forgery. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. There is ongoing doubt regarding the real existence of this vulnerability. The project maintainer explains (translated from Chinese): "Triggers are manually activated and involve login and access control, thus requiring management." The pull request by the researcher got rejected because of that.

🤖 AI Executive Summary

CVE-2026-7305 is a Server-Side Request Forgery (SSRF) vulnerability in Xuxueli xxl-job versions up to 3.3.2 affecting the triggerJob function through the addressList parameter. The vulnerability requires authentication and manual trigger activation, limiting its practical exploitability in real-world scenarios.

📄 Description (Arabic)

تم تحديد ثغرة Server-Side Request Forgery (SSRF) في Xuxueli xxl-job حتى الإصدار 3.3.2 في وظيفة triggerJob بملف XxlJobServiceImpl.java. تسمح الثغرة بمعالجة معامل addressList بطريقة تمكن المهاجمين المصرحين من إجراء طلبات غير مصرح بها إلى الأنظمة الداخلية. يتطلب الاستغلال المصادقة والوصول الإداري، مما يقلل من خطورتها العملية.

🤖 ملخص تنفيذي (AI)

This SSRF vulnerability in xxl-job's trigger endpoint could allow authenticated attackers to make unauthorized requests to internal systems. The vulnerability's impact is mitigated by authentication requirements and access controls implemented by the maintainers.

🤖 AI Intelligence Analysis Analyzed: May 18, 2026 07:31
🇸🇦 Saudi Arabia Impact Assessment
Saudi Relevance: medium
🏢 Affected Saudi Sectors
banking telecom energy government healthcare
🎯 MITRE ATT&CK Techniques
⚖️ Saudi Risk Score (AI)
6.0
/ 10.0
🔧 Remediation Steps (English)
Update Xuxueli xxl-job to version 3.3.3 or later. Implement network segmentation to restrict outbound connections from job scheduler servers. Apply strict input validation on the addressList parameter. Monitor and log all trigger activities. Restrict access to the trigger endpoint to authorized administrators only.
🔧 خطوات المعالجة (العربية)
قم بتحديث Xuxueli xxl-job إلى الإصدار 3.3.3 أو أحدث. طبق تقسيم الشبكة لتقييد الاتصالات الصادرة من خوادم جدولة المهام. طبق التحقق الصارم من صحة المدخلات على معامل addressList. راقب وسجل جميع أنشطة التشغيل. قيد الوصول إلى نقطة نهاية التشغيل للمسؤولين المصرحين فقط.
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
5.1 5.2 5.3
🔵 SAMA CSF
ID.AM-2 PR.AC-1 PR.AC-3
🟡 ISO 27001:2022
A.6.1.2 A.9.1.1 A.9.2.1 A.13.1.3
📊 CVSS Score
6.3
/ 10.0 — Medium
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredL — Low / Local
User InteractionN — None / Network
ScopeU — Unchanged
ConfidentialityL — Low / Local
IntegrityL — Low / Local
AvailabilityL — Low / Local
📋 Quick Facts
Severity Medium
CVSS Score6.3
CWECWE-918
EPSS0.05%
Exploit No
Patch ✗ No
Published 2026-04-28
Source Feed nvd
🇸🇦 Saudi Risk Score
6.0
/ 10.0 — Saudi Risk
Priority: MEDIUM
🏷️ Tags
CWE-918
Share this CVE
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.