CVE-2026-3733 | xuxueli xxl-job up to 3.3.2 JobInfoController.java server-side request forgery (Issue 3924 / EUVD-2026-10236)
A vulnerability was found in xuxueli xxl-job up to 3.3.2 and classified as critical. This impacts an unknown function of the file source-code/src/main/java/com/xxl/job/admin/controller/JobInfoController.java. The manipulation results in server-side request forgery.
This vulnerability is known as CVE-2026-3733. It is possible to launch the attack remotely. Furthermore, an exploit is available.
The project maintainer closed the issue report with the following statement: "Access token security verification is required." (translated from Chinese)