PatchSiren cyber security CVE debrief
CVE-2026-5739 PowerJob CVE debrief
CVE-2026-5739 is a code injection vulnerability in PowerJob 5.1.0/5.1.1/5.1.2's OpenAPI Endpoint. The vulnerability has a CVSS score of 6.9 and a severity of MEDIUM. The affected element is the function GroovyEvaluator.evaluate of the file /openApi/addWorkflowNode of the component OpenAPI Endpoint. The manipulation of the argument nodeParams results in code injection. The attack can be executed remotely. Users of PowerJob 5.1.0/5.1.1/5.1.2 should review and apply patches or mitigations to prevent code injection attacks via the OpenAPI Endpoint.
- Vendor
- PowerJob
- Product
- PowerJob
- CVSS
- MEDIUM 6.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-07
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-07
- Advisory updated
- 2026-07-24
Who should care
Users of PowerJob 5.1.0/5.1.1/5.1.2 should review and apply patches or mitigations to prevent code injection attacks via the OpenAPI Endpoint. The vulnerability has a CVSS score of 6.9 and a severity of MEDIUM, indicating a medium priority for remediation. The vulnerability can be exploited remotely, which increases the risk of attack.
Technical summary
The vulnerability is caused by a flaw in the GroovyEvaluator.evaluate function of the /openApi/addWorkflowNode endpoint. The manipulation of the nodeParams argument results in code injection, which can be executed remotely. The affected product, PowerJob, is a job management system that allows users to manage and monitor their tasks and workflows. The vulnerability has a CVSS score of 6.9 and a severity of MEDIUM.
Defensive priority
Medium priority due to CVSS score of 6.9 and potential for remote code injection.
Recommended defensive actions
- Review and apply patches or mitigations for PowerJob 5.1.0/5.1.1/5.1.2
- Monitor OpenAPI Endpoint usage for suspicious activity
- Implement compensating controls to prevent code injection attacks
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
Evidence notes
The CVE record and NVD entry provide limited information about the vulnerability. Further investigation and verification are necessary to fully understand the scope and impact of the vulnerability. The affected product, PowerJob, is a job management system that allows users to manage and monitor their tasks and workflows. The vulnerability is caused by a flaw in the GroovyEvaluator.evaluate function of the /openApi/addWorkflowNode endpoint, which allows for code injection. The manipulation of the nodeParams argument results in code injection, which can be executed remotely. The project was informed of the problem early through an issue report but has not responded yet. The CVE record was published on 2026-04-07T20:16:34.647Z and has not been modified since then.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-07T20:16:34.647Z and has not been modified since then.