CVE-2026-7303
Raw vector
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XSummary
CVE-2026-7303 is a low-severity Resource Injection (CWE-99) vulnerability. Its CVSS base score is 2.9 (Low).
Operationally, exploitation aligns with the MITRE ATT&CK technique Exploit Public-Facing Application (T1190); ranked at the 35th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
The strongest mitigations our analysis identified map to SI-10 (Information Input Validation) and AC-3 (Access Enforcement) — see the control section below for these in your framework.
OWASP Top 10 for Web (2025)
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2026-26148
Vulnerability Data
A security flaw has been discovered in Xuxueli xxl-job up to 3.3.2. Impacted is the function logDetailCat of the file xxl-job-admin/src/main/java/com/xxl/job/admin/controller/biz/JobLogController.java of the component Execution Log Handler. The manipulation of the argument logId results in improper control of resource identifiers.…
more
The attack may be performed from remote. This attack is characterized by high complexity. The exploitability is considered difficult. The exploit has been released to the public and may be used for attacks. Upgrading to version 3.4.0 is recommended to address this issue. The patch is identified as d24e4ccd6073cc75305e1d3b9c29bc8db7437e7a. It is suggested to upgrade the affected component.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise Techniques
CVEs Like This One
Affected Assets
Mitigating Controls
Control response
—
—
—
V1.3.8V1.3.9V1.3.11V9.2.2
Mitigating Controls (NIST 800-53 r5) AI
Directly requires validation of inputs before they are accepted as resource identifiers.
Enforces authorizations on resource access so an injected identifier cannot reach outside the intended sphere.
Enforces information flow rules that block use of untrusted identifiers to reach unauthorized resources.
Mitigating Controls (NIST CSF 2.0) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.
Secure SDLC practices directly require input validation and sanitization that prevent resource-identifier injection flaws.
Least-privilege access policy and enforcement limits damage from injected resource identifiers even when input validation is absent.
Network segmentation and unauthorized-access controls reduce the blast radius of successful resource injection.
Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.
Security testing can detect resource-injection flaws but does not itself implement preventive controls.
Secure SDLC mandates input validation and resource-identifier sanitization that directly prevents resource injection.
Application security requirements explicitly call for controls on external identifiers used to access resources.
Secure architecture principles reduce attack surface for resource injection but do not prescribe identifier validation.
Secure coding standards require strict validation and whitelisting of all resource identifiers before use.
Information-access-restriction policies limit which resources can be referenced, indirectly reducing injection impact.