CVE-2026-91925: Polyaxon through 2.16.4 Server-Side Template Injection via Unsandboxed Jinja2 Engine

Published Sep 15, 2026
·
Updated

Polyaxon through 2.16.4 renders operation specification fields with an unsandboxed Jinja2 environment during server-side run preparation, allowing authenticated users to execute arbitrary code. Attackers can submit runs with Jinja2 payloads in queue, namespace, conditions, presets, or dependencies fields to execute operating system commands in the scheduler process context, exposing database credentials and service tokens.

Affected Software

1 affected component
Polyaxon<=2.16.4

Event History

Sep 15, 2026
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An authenticated Polyaxon user who can submit a run can exploit it by placing a Jinja2 payload in an affected operation specification field.

2

Which operation specification fields are affected?

The affected fields identified are queue, namespace, conditions, presets, and dependencies.

3

What level of access could successful exploitation provide?

Payloads can execute operating system commands in the scheduler process context. This can expose database credentials and service tokens, with high impact to confidentiality, integrity, and availability.

4

Are deployments running a default configuration affected?

The provided information identifies rendering through an unsandboxed Jinja2 environment during server-side run preparation, but does not state whether this behavior requires a non-default configuration.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203