Skip to main content
Vulnerability Database/CVE-2026-75430

CVE-2026-75430: PowerJob Worker RCE Vulnerability

CVE-2026-75430 is an unauthenticated remote code execution flaw in PowerJob Worker 5.1.2 that exposes the /worker/deployContainer endpoint. This post explains its technical details, affected versions, and mitigation steps.

Published:

CVE-2026-75430 Overview

CVE-2026-75430 is an unauthenticated remote code execution vulnerability in PowerJob Worker version 5.1.2 and likely earlier releases. The PowerJob Worker exposes the /worker/deployContainer HTTP endpoint on its default transport port without any authentication check. A remote attacker who can reach the worker over the network can invoke this endpoint to deploy an arbitrary container and execute code within the worker process. The flaw is categorized under CWE-306: Missing Authentication for Critical Function.

Critical Impact

Any network-reachable PowerJob Worker running 5.1.2 or earlier can be fully compromised by an unauthenticated attacker, leading to arbitrary code execution on the host.

Affected Products

  • PowerJob Worker 5.1.2
  • PowerJob Worker versions prior to 5.1.2 (likely affected)
  • Deployments exposing the default worker transport port to untrusted networks

Discovery Timeline

  • 2026-09-04 - CVE-2026-75430 published to the National Vulnerability Database
  • 2026-09-08 - Last updated in NVD database

Technical Details for CVE-2026-75430

Vulnerability Analysis

PowerJob is a distributed task scheduling and computing framework written in Java. The worker component receives tasks and container deployment instructions from the PowerJob server over an HTTP transport. In version 5.1.2 the /worker/deployContainer endpoint accepts container deployment requests without validating the identity or authorization of the caller.

The deployContainer action instructs the worker to fetch and load an OmsContainer, which is a JAR-packaged unit of Java code executed inside the worker JVM. Because the handler does not authenticate the request, any client that can send HTTP traffic to the worker port can trigger the code loading path and gain arbitrary code execution on the host.

Root Cause

The root cause is missing authentication on a security-critical function. The WorkerActor request handler dispatches deployContainer messages to OmsContainerFactory without verifying that the caller is the trusted PowerJob server. Container deployment loads attacker-controlled Java code into the worker, so the absence of an authentication check converts a management operation into an unauthenticated RCE primitive. See the PowerJob Worker Actor code and the OmsContainerFactory code for the vulnerable code paths.

Attack Vector

Exploitation is performed over the network with no authentication and no user interaction. An attacker sends a crafted HTTP POST request to the worker's /worker/deployContainer endpoint referencing a container artifact under the attacker's control. The worker downloads the artifact and instantiates the container, executing the embedded Java code with the privileges of the worker process. A public proof-of-concept illustrating the request structure is available in a GitHub Gist.

Detection Methods for CVE-2026-75430

Indicators of Compromise

  • Unexpected HTTP POST requests to /worker/deployContainer on the PowerJob Worker transport port originating from hosts other than the trusted PowerJob server.
  • New or unknown JAR files appearing under the worker's container storage directory following inbound HTTP activity.
  • Child processes spawned by the worker JVM performing reconnaissance, credential access, or outbound network connections not associated with legitimate job execution.

Detection Strategies

  • Inspect HTTP access and application logs for requests to the deployContainer route and correlate source addresses against the authorized PowerJob server inventory.
  • Alert on OmsContainerFactory container load events that are not preceded by a legitimate deployment workflow initiated from the PowerJob server.
  • Baseline outbound network activity from PowerJob Worker hosts and flag deviations, such as pulls of JAR artifacts from unknown hosts.

Monitoring Recommendations

  • Forward PowerJob Worker application logs and host process telemetry to a central analytics platform for correlation with network flow data.
  • Monitor for JVM child process creation events (java -> sh, java -> cmd.exe, java -> curl/wget) on worker hosts.
  • Track listening sockets and remote connections to worker transport ports to identify unexpected exposure to untrusted networks.

How to Mitigate CVE-2026-75430

Immediate Actions Required

  • Restrict network access to PowerJob Worker transport ports so only the trusted PowerJob server can reach /worker/deployContainer.
  • Inventory all PowerJob Worker instances and identify any exposed to internal user networks, DMZs, or the internet.
  • Review worker hosts for signs of unauthorized container deployment or post-exploitation activity as described in the detection section.

Patch Information

At the time of publication no fixed version is referenced in the NVD entry. Monitor the PowerJob GitHub repository and the project's security policy for an official fix and upgrade guidance. Apply the vendor patch once released and validate that authentication is enforced on the deployContainer endpoint.

Workarounds

  • Place PowerJob Worker instances on an isolated network segment and use firewall rules or security groups to permit inbound traffic only from the PowerJob server.
  • Terminate the worker transport behind a reverse proxy that enforces mutual TLS or an authenticated allowlist for the deployContainer route.
  • Run worker processes with the least privileges required and on hardened hosts to reduce the blast radius of successful exploitation.
bash
# Example: restrict inbound access to the PowerJob Worker transport port
# Replace 10.0.0.10 with the PowerJob server address and 27777 with the worker port in use
iptables -A INPUT -p tcp --dport 27777 -s 10.0.0.10 -j ACCEPT
iptables -A INPUT -p tcp --dport 27777 -j DROP

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.