Skip to main content
Vulnerability Database/CVE-2026-75429

CVE-2026-75429: PowerJob RCE Vulnerability

CVE-2026-75429 is an unauthenticated remote code execution vulnerability in PowerJob versions 4.x through 5.1.2 affecting the /friend/process endpoint. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2026-75429 Overview

CVE-2026-75429 is an unauthenticated remote code execution vulnerability affecting PowerJob versions 4.x through 5.1.2. The flaw resides in the /friend/process endpoint of the Server-Worker transport layer. Attackers can reach this endpoint over the network without credentials and execute arbitrary code on the affected PowerJob server. PowerJob is a distributed task scheduling framework widely deployed in Java-based production environments, which increases the exposure surface of vulnerable installations.

Critical Impact

Unauthenticated attackers can achieve remote code execution against PowerJob 4.x through 5.1.2 by sending crafted requests to the /friend/process endpoint.

Affected Products

  • PowerJob 4.x (all releases)
  • PowerJob 5.0.x
  • PowerJob 5.1.0 through 5.1.2

Discovery Timeline

  • 2026-09-04 - CVE-2026-75429 published to the National Vulnerability Database (NVD)
  • 2026-09-08 - Last updated in NVD database
  • 2026-09-13 - Exploit Prediction Scoring System (EPSS) data recorded

Technical Details for CVE-2026-75429

Vulnerability Analysis

The vulnerability resides in the Server-Worker transport layer used by PowerJob to coordinate scheduled jobs between the central server and distributed workers. The /friend/process endpoint accepts requests without authentication and processes attacker-controlled payloads. Because the endpoint is part of the internal transport channel, it is exposed on the PowerJob server port and reachable by any client that can connect to the service.

Exploitation results in arbitrary code execution in the context of the PowerJob server process. Successful attacks allow command execution, credential theft, lateral movement into connected worker fleets, and tampering with scheduled jobs. PowerJob instances are frequently deployed inside container platforms, so a compromised server can be used to pivot into orchestrated environments.

Root Cause

The root cause is the combination of missing authentication on a sensitive server endpoint and unsafe processing of externally supplied data within the Server-Worker transport handler. The /friend/process handler trusts inbound messages that were designed for internal cluster peers, allowing an external caller to invoke code paths that should be restricted to authenticated workers.

Attack Vector

The attack vector is network based and requires no privileges or user interaction. An attacker sends a crafted HTTP request to the PowerJob server's /friend/process endpoint. The server deserializes and processes the payload, which leads to code execution. Public proof-of-concept material is referenced by the GitHub Gist PoC Repository. Additional context on the affected component is available in the GitHub PowerJob Project and the GitHub PowerJob Docker Compose File.

No verified exploitation code is reproduced here. Review the linked references for technical detail.

Detection Methods for CVE-2026-75429

Indicators of Compromise

  • Inbound HTTP requests targeting the /friend/process path on PowerJob server ports from unexpected source addresses.
  • Unexpected child processes spawned by the PowerJob server JVM, such as shells, curl, wget, or scripting interpreters.
  • New or modified scheduled jobs in PowerJob that were not created by authorized operators.
  • Outbound connections from PowerJob hosts to attacker infrastructure following requests to the vulnerable endpoint.

Detection Strategies

  • Alert on any request to /friend/process originating from outside the trusted worker network segment.
  • Correlate HTTP access logs on PowerJob servers with process creation telemetry to identify request-triggered command execution.
  • Baseline PowerJob JVM behavior and flag deviations such as new outbound sockets, file writes to sensitive paths, or execution of native binaries.

Monitoring Recommendations

  • Ingest PowerJob server access logs and container runtime events into a centralized analytics platform.
  • Monitor for scheduled task modifications and job registrations that lack a corresponding authenticated operator session.
  • Track network flows to and from PowerJob server ports to detect exposure of the transport layer to untrusted networks.

How to Mitigate CVE-2026-75429

Immediate Actions Required

  • Restrict network access to PowerJob server ports so that only trusted worker nodes and administrators can reach the transport layer.
  • Block or filter external requests to the /friend/process endpoint at reverse proxies, ingress controllers, or web application firewalls.
  • Audit PowerJob servers for signs of unauthorized job creation, unexpected child processes, and outbound connections to unknown hosts.
  • Rotate any credentials, tokens, or keys accessible to the PowerJob server process if compromise is suspected.

Patch Information

At the time of publication, the enriched CVE data does not list a fixed version. Monitor the GitHub PowerJob Project for release notes and security advisories addressing versions 4.x through 5.1.2. Upgrade to the first release that documents a fix for CVE-2026-75429 and validate that the /friend/process endpoint enforces authentication after the update.

Workarounds

  • Place PowerJob servers behind a private network segment or VPN that is unreachable from the internet and untrusted internal zones.
  • Enforce mutual TLS or IP allow lists between PowerJob servers and workers using a reverse proxy in front of the transport port.
  • Deny requests to /friend/process at the proxy layer for any source that is not an authorized worker.
  • Run the PowerJob server as a low-privilege user inside a hardened container to limit the blast radius of successful exploitation.
bash
# Example NGINX snippet restricting access to the vulnerable endpoint
location = /friend/process {
    allow 10.0.0.0/24;    # trusted PowerJob worker subnet
    deny  all;
    proxy_pass http://powerjob_server_upstream;
}

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.