PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-5739 PowerJob CVE debrief

CVE-2026-5739 is a code injection vulnerability in PowerJob 5.1.0/5.1.1/5.1.2's OpenAPI Endpoint. The vulnerability has a CVSS score of 6.9 and a severity of MEDIUM. The affected element is the function GroovyEvaluator.evaluate of the file /openApi/addWorkflowNode of the component OpenAPI Endpoint. The manipulation of the argument nodeParams results in code injection. The attack can be executed remotely. Users of PowerJob 5.1.0/5.1.1/5.1.2 should review and apply patches or mitigations to prevent code injection attacks via the OpenAPI Endpoint.

Vendor
PowerJob
Product
PowerJob
CVSS
MEDIUM 6.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-07
Original CVE updated
2026-07-24
Advisory published
2026-04-07
Advisory updated
2026-07-24

Who should care

Users of PowerJob 5.1.0/5.1.1/5.1.2 should review and apply patches or mitigations to prevent code injection attacks via the OpenAPI Endpoint. The vulnerability has a CVSS score of 6.9 and a severity of MEDIUM, indicating a medium priority for remediation. The vulnerability can be exploited remotely, which increases the risk of attack.

Technical summary

The vulnerability is caused by a flaw in the GroovyEvaluator.evaluate function of the /openApi/addWorkflowNode endpoint. The manipulation of the nodeParams argument results in code injection, which can be executed remotely. The affected product, PowerJob, is a job management system that allows users to manage and monitor their tasks and workflows. The vulnerability has a CVSS score of 6.9 and a severity of MEDIUM.

Defensive priority

Medium priority due to CVSS score of 6.9 and potential for remote code injection.

Recommended defensive actions

  • Review and apply patches or mitigations for PowerJob 5.1.0/5.1.1/5.1.2
  • Monitor OpenAPI Endpoint usage for suspicious activity
  • Implement compensating controls to prevent code injection attacks
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed

Evidence notes

The CVE record and NVD entry provide limited information about the vulnerability. Further investigation and verification are necessary to fully understand the scope and impact of the vulnerability. The affected product, PowerJob, is a job management system that allows users to manage and monitor their tasks and workflows. The vulnerability is caused by a flaw in the GroovyEvaluator.evaluate function of the /openApi/addWorkflowNode endpoint, which allows for code injection. The manipulation of the nodeParams argument results in code injection, which can be executed remotely. The project was informed of the problem early through an issue report but has not responded yet. The CVE record was published on 2026-04-07T20:16:34.647Z and has not been modified since then.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-07T20:16:34.647Z and has not been modified since then.