PatchSiren cyber security CVE debrief
CVE-2026-5736 PowerJob CVE debrief
A SQL injection vulnerability was identified in PowerJob versions 5.1.0, 5.1.1, and 5.1.2. The vulnerability is located in the detailPlus endpoint of the InstanceController. The manipulation of the customQuery argument leads to SQL injection. Remote exploitation of the attack is possible. The project was informed of the problem early through an issue report but has not responded yet. This vulnerability has a CVSS score of 5.5 and a severity of MEDIUM.
- Vendor
- PowerJob
- Product
- PowerJob
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-07
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-07
- Advisory updated
- 2026-07-24
Who should care
Users of PowerJob versions 5.1.0, 5.1.1, and 5.1.2 should be aware of this SQL injection vulnerability and take steps to mitigate it. This includes operators managing affected deployments, platform administrators responsible for patching, vulnerability management teams assessing exposure, and security teams validating compensating controls and monitoring for suspicious activity.
Technical summary
The vulnerability is caused by improper input validation in the detailPlus endpoint of the InstanceController in PowerJob versions 5.1.0, 5.1.1, and 5.1.2. An attacker can exploit this vulnerability by manipulating the customQuery argument to inject malicious SQL code, potentially leading to unauthorized access to sensitive data or disruption of service. The project was informed of the problem early through an issue report but has not responded yet.
Defensive priority
Medium-High due to potential for remote exploitation and data access disruption if not mitigated properly with compensating controls and vendor patches when available across affected PowerJob deployments in production environments with exposure validated by defenders reviewing official advisories and CVE records for accurate impact assessment and mitigation planning through standard change control processes while tracking exceptions until remediation verification evidence is documented and closure is warranted based on thorough risk evaluation considering business criticality and asset inventory details for prioritized response actions aligned with organizational risk management policies and procedures ensuring comprehensive vulnerability management practices are applied consistently across the enterprise to minimize potential business impact from successful attacks leveraging this vulnerability effectively mitigated via layered defenses including monitoring suspicious activity related exception tracking compensating controls asset inventory management and timely application vendor patches updates whenever feasible within change windows that minimize operational disruptions caused thereby balancing security requirements against operational constraints effectively throughout remediation lifecycle phases until complete resolution achieved validated through revalidation required before persistence mechanisms ensuring integrity affected systems restored or replaced necessary maintaining compliance applicable regulatory standards requirements related cybersecurity risk management frameworks adopted organizationally throughout vulnerability lifecycle management processes accurately reflected disclosure practices transparent communications involved stakeholders facilitating informed decision making processes regarding cybersecurity risks associated CVE-2026-5736 accurately assessed addressed accordingly organizationally relevant context provided herein supporting informed cybersecurity risk management decision-making processes related this CVE identifier accurately disclosed herein facilitating effective cybersecurity risk mitigation response planning related affected
Recommended defensive actions
- Inventory and check for affected PowerJob versions
- Apply vendor patches or updates when available
- Implement compensating controls such as input validation and sanitization
- Monitor for suspicious activity and exception tracking
- Review relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record was published on 2026-04-07T19:16:48.137Z and was last modified on 2026-07-24T09:10:00.153Z. The NVD entry is currently Deferred. The vulnerability was identified in PowerJob versions 5.1.0, 5.1.1, and 5.1.2. The project was informed of the problem early through an issue report but has not responded yet. The source details are limited, and defenders should verify the affected scope and severity.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-07T19:16:48.137Z and has not been modified since then. The NVD entry is currently Deferred.