CVE-2026-75429: PowerJob vulnerability
Published Sep 4, 2026
·Updated
PowerJob versions 4.x through 5.1.2 contain an unauthenticated remote code execution vulnerability in the /friend/process endpoint of the Server-Worker transport layer
Affected Software
1 affected component
PowerJob>=4.0<=5.1.2
Event History
Sep 4, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
Which deployments are exposed to this issue?
PowerJob versions 4.x through 5.1.2 are affected where the Server-Worker transport layer's /friend/process endpoint is reachable by an attacker.
2
What access does an attacker need to exploit it?
The vulnerability is unauthenticated, so an attacker does not need valid PowerJob credentials to target the affected endpoint. They need network access to /friend/process on the Server-Worker transport layer.