What is CVE-2026-52371?
CVE-2026-52371 is a Server-Side Request Forgery (SSRF) vulnerability in the `xxl-job-admin/jobinfo/trigger` component of xxl-job v3.4.0. It allows authenticated attackers to scan internal network resources by providing a crafted HTTP request. It is recommended to update xxl-job to the latest version to mitigate this issue.
Azərbaycanca: CVE-2026-52371 xxl-job v3.4.0 versiyasının `xxl-job-admin/jobinfo/trigger` komponentində Server-Side Request Forgery (SSRF) zəifliyidir. Bu, autentifikasiya olunmuş hücumçulara xüsusi HTTP sorğu göndərərək daxili şəbəkə resurslarını skan etməyə imkan verir. Təsirə məruz qalmamaq üçün xxl-job-u ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
Does exploiting CVE-2026-52371 require authentication?
Yes, CVE-2026-52371 is an SSRF vulnerability in xxl-job v3.4.0 that allows authenticated attackers to scan internal network resources.
How to mitigate the CVE-2026-52371 vulnerability?
It is recommended to update xxl-job to the latest version to mitigate this issue.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.