CVE-2026-75430 Overview
CVE-2026-75430 is an unauthenticated remote code execution vulnerability in PowerJob Worker version 5.1.2 and likely earlier releases. The PowerJob Worker exposes the /worker/deployContainer HTTP endpoint on its default transport port without any authentication check. A remote attacker who can reach the worker over the network can invoke this endpoint to deploy an arbitrary container and execute code within the worker process. The flaw is categorized under CWE-306: Missing Authentication for Critical Function.
Critical Impact
Any network-reachable PowerJob Worker running 5.1.2 or earlier can be fully compromised by an unauthenticated attacker, leading to arbitrary code execution on the host.
Affected Products
- PowerJob Worker 5.1.2
- PowerJob Worker versions prior to 5.1.2 (likely affected)
- Deployments exposing the default worker transport port to untrusted networks
Discovery Timeline
- 2026-09-04 - CVE-2026-75430 published to the National Vulnerability Database
- 2026-09-08 - Last updated in NVD database
Technical Details for CVE-2026-75430
Vulnerability Analysis
PowerJob is a distributed task scheduling and computing framework written in Java. The worker component receives tasks and container deployment instructions from the PowerJob server over an HTTP transport. In version 5.1.2 the /worker/deployContainer endpoint accepts container deployment requests without validating the identity or authorization of the caller.
The deployContainer action instructs the worker to fetch and load an OmsContainer, which is a JAR-packaged unit of Java code executed inside the worker JVM. Because the handler does not authenticate the request, any client that can send HTTP traffic to the worker port can trigger the code loading path and gain arbitrary code execution on the host.
Root Cause
The root cause is missing authentication on a security-critical function. The WorkerActor request handler dispatches deployContainer messages to OmsContainerFactory without verifying that the caller is the trusted PowerJob server. Container deployment loads attacker-controlled Java code into the worker, so the absence of an authentication check converts a management operation into an unauthenticated RCE primitive. See the PowerJob Worker Actor code and the OmsContainerFactory code for the vulnerable code paths.
Attack Vector
Exploitation is performed over the network with no authentication and no user interaction. An attacker sends a crafted HTTP POST request to the worker's /worker/deployContainer endpoint referencing a container artifact under the attacker's control. The worker downloads the artifact and instantiates the container, executing the embedded Java code with the privileges of the worker process. A public proof-of-concept illustrating the request structure is available in a GitHub Gist.
Detection Methods for CVE-2026-75430
Indicators of Compromise
- Unexpected HTTP POST requests to /worker/deployContainer on the PowerJob Worker transport port originating from hosts other than the trusted PowerJob server.
- New or unknown JAR files appearing under the worker's container storage directory following inbound HTTP activity.
- Child processes spawned by the worker JVM performing reconnaissance, credential access, or outbound network connections not associated with legitimate job execution.
Detection Strategies
- Inspect HTTP access and application logs for requests to the deployContainer route and correlate source addresses against the authorized PowerJob server inventory.
- Alert on OmsContainerFactory container load events that are not preceded by a legitimate deployment workflow initiated from the PowerJob server.
- Baseline outbound network activity from PowerJob Worker hosts and flag deviations, such as pulls of JAR artifacts from unknown hosts.
Monitoring Recommendations
- Forward PowerJob Worker application logs and host process telemetry to a central analytics platform for correlation with network flow data.
- Monitor for JVM child process creation events (java -> sh, java -> cmd.exe, java -> curl/wget) on worker hosts.
- Track listening sockets and remote connections to worker transport ports to identify unexpected exposure to untrusted networks.
How to Mitigate CVE-2026-75430
Immediate Actions Required
- Restrict network access to PowerJob Worker transport ports so only the trusted PowerJob server can reach /worker/deployContainer.
- Inventory all PowerJob Worker instances and identify any exposed to internal user networks, DMZs, or the internet.
- Review worker hosts for signs of unauthorized container deployment or post-exploitation activity as described in the detection section.
Patch Information
At the time of publication no fixed version is referenced in the NVD entry. Monitor the PowerJob GitHub repository and the project's security policy for an official fix and upgrade guidance. Apply the vendor patch once released and validate that authentication is enforced on the deployContainer endpoint.
Workarounds
- Place PowerJob Worker instances on an isolated network segment and use firewall rules or security groups to permit inbound traffic only from the PowerJob server.
- Terminate the worker transport behind a reverse proxy that enforces mutual TLS or an authenticated allowlist for the deployContainer route.
- Run worker processes with the least privileges required and on hardened hosts to reduce the blast radius of successful exploitation.
# Example: restrict inbound access to the PowerJob Worker transport port
# Replace 10.0.0.10 with the PowerJob server address and 27777 with the worker port in use
iptables -A INPUT -p tcp --dport 27777 -s 10.0.0.10 -j ACCEPT
iptables -A INPUT -p tcp --dport 27777 -j DROP
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.