---
id: CVE-2026-90488
title: A vulnerability was determined in Xuxueli xxl-job up to 3.4.2
summary: >-
  A vulnerability was determined in Xuxueli xxl-job up to 3.4.2. This affects
  the function GroovyClassLoader.parseClass of the file
  xxl-job-core/src/main/java/com/xxl/job/core/glue/GlueFactory.java. This
  manipulation causes code injection.…
severity: medium
cvss: 6.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-74
  - CWE-94
vendor: Xuxueli
product: xxl-job
affected:
  - xxl-job 3.4.0
  - xxl-job 3.4.1
  - xxl-job 3.4.2
published: '2026-09-13'
updated: '2026-09-15'
sourceUpdated: '2026-09-15T15:17:27.203'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90488'
references:
  - url: >-
      https://github.com/zhaizejiang/xxl-job-vuln-poc/blob/main/xxl-job%20v3.4.2%20Remote%20Code%20Execution%20via%20Groovy%20Code%20Execution.md
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-90488'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/888470'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/403076'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/403076/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
  - exploit-available
epss: 0.00228
epssPercentile: 0.13785
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-15T13:42:31.349788Z'
ingestedAt: '2026-09-14T15:23:07.477Z'
---

## Overview

A vulnerability was determined in Xuxueli xxl-job up to 3.4.2. This affects the function GroovyClassLoader.parseClass of the file xxl-job-core/src/main/java/com/xxl/job/core/glue/GlueFactory.java. This manipulation causes code injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
