PatchSiren

PowerJob CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM PowerJob CVE published 2026-08-31

CVE-2026-82630

CVE-2026-82630 is a server-side request forgery vulnerability in PowerJob up to 5.1.2, specifically affecting MuConnectionManager.getOrCreateConnection. The vulnerability allows for remote exploitation and a public exploit is available. This could lead to unauthorized actions on the server, potentially compromising data integrity or confidentiality. Organizations should prioritize verification of their in [truncated]

MEDIUM PowerJob CVE published 2026-04-07

CVE-2026-5739

CVE-2026-5739 is a code injection vulnerability in PowerJob 5.1.0/5.1.1/5.1.2's OpenAPI Endpoint. The vulnerability has a CVSS score of 6.9 and a severity of MEDIUM. The affected element is the function GroovyEvaluator.evaluate of the file /openApi/addWorkflowNode of the component OpenAPI Endpoint. The manipulation of the argument nodeParams results in code injection. The attack can be executed remotely. [truncated]

MEDIUM PowerJob CVE published 2026-04-07

CVE-2026-5736

A SQL injection vulnerability was identified in PowerJob versions 5.1.0, 5.1.1, and 5.1.2. The vulnerability is located in the detailPlus endpoint of the InstanceController. The manipulation of the customQuery argument leads to SQL injection. Remote exploitation of the attack is possible. The project was informed of the problem early through an issue report but has not responded yet. This vulnerability ha [truncated]