CVE-2026-3733Disclosure

LOWCVSS 2.1 · LOW

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was detected in xuxueli xxl-job up to 3.3.2. This impacts an unknown function of the file source-code/src/main/java/com/xxl/job/admin/controller/JobInfoController.java. The manipulation results in server-side request forgery. It is possible to launch the attack remotely. The exploit is now public and may be used. The project maintainer closed the issue report with the following statement: "Access token security verification is required." (translated from Chinese)

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 5 classified signals
  • Peaked 1d ago at 3 mentions (2026-03-08); latest day: 2
  • 5 total mentions across 2 days

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-03-08: 3Mentions · 2026-05-19: 2Technical Details · 2026-03-08: 2Technical Details · 2026-05-19: 203-0805-19
Signal classification1 categories
Disclosure
5100.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-083
Disclosure3
2026-05-192
Disclosure2
Full discourse5 posts
  • Geng Yang@geng_zast
    Disclosure

    http://ZAST.AI identified and verified `CVE-2026-3733` in `XXL-JOB`. An admin trigger field in `/jobinfo/trigger` ended up acting like a live remoting destination. That is how routine scheduling metadata became SSRF surface. https://t.co/owCIdcTNdC

    Post summary

    ZAST.AI identified a new SSRF vulnerability (CVE-2026-3733) in XXL-JOB where an admin trigger field can be used as a live remoting destination, enabling SSRF attacks.

    1000058
    49 followersView on X
  • ZAST AI@zast_ai
    Disclosure

    Security note: ZAST identified and verified `CVE-2026-3733` in `XXL-JOB`. The admin trigger flow accepted `addressList` and used it to drive an outbound server request. That created an SSRF path. https://t.co/ciQ7eP83JK

    Post summary

    ZAST identified its SSRF vulnerability (CVE-2026-3733) in XXL-JOB, noting that the admin trigger flow accepts an addressList and uses it to make outbound server requests, creating a potential SSRF path.

    1000074
    36 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3733 A vulnerability was detected in xuxueli xxl-job up to 3.3.2. This impacts an unknown function of the file source-code/src/main/java/com/xxl/job/admin/controller/JobInfo… https://www.cve.org/CVERecord?id=CVE-2026-3733

    Post summary

    A new vulnerability (CVE‑2026‑3733) has been identified in xuxueli xxl‑job up to version 3.3.2, affecting an unspecified function in the JobInfo controller, with no further details or patches disclosed.

    00000100
    56.6K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-3733 - xuxueli xxl-job http://JobInfoController.java server-side request forgery Intel Report: https://ift.tt/zmJ0arZ

    Post summary

    The alert announces a newly disclosed CVE‑2026‑3733 affecting xuxueli xxl‑job, identified as a server‑side request forgery, with an Intel report link but no evidence of exploitation, PoC, or patch details.

    0000037
    347 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-3733 Server-Side Request Forgery in XXL-Job Admin Controller Before Version 3.3.2 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3733

    Post summary

    The text announces a new SSRF vulnerability (CVE‑2026‑3733) affecting XXL‑Job Admin Controller prior to version 3.3.2, providing basic technical details but no PoC, exploit, or mitigation information.

    0000052
    4.0K followersView on X

Explore more