CVE-2026-75431 Overview
CVE-2026-75431 affects PowerJob Server version 5.1.2 and likely earlier releases. The vulnerability stems from the use of a predictable JWT (JSON Web Token) signing key for HS256-based authentication. A remote attacker can forge valid authentication tokens and gain unauthorized access to the server. Successful exploitation allows arbitrary code execution on the PowerJob Server. The flaw is classified under CWE-321: Use of Hard-coded Cryptographic Key.
Critical Impact
Remote unauthenticated attackers can forge JWT tokens using the predictable HS256 signing key, bypass authentication, and execute arbitrary code on affected PowerJob Server instances.
Affected Products
- PowerJob Server version 5.1.2
- PowerJob Server versions prior to 5.1.2 (likely affected)
- Deployments using default configuration from the PowerJob docker-compose file
Discovery Timeline
- 2026-09-04 - CVE CVE-2026-75431 published to NVD
- 2026-09-08 - Last updated in NVD database
Technical Details for CVE-2026-75431
Vulnerability Analysis
PowerJob is an open-source distributed task scheduling framework. The server component uses JWT for authentication of administrative and OpenAPI operations. The DefaultSecretProvider implementation supplies a predictable secret used by JwtServiceImpl to sign HS256 tokens. Because HS256 is a symmetric algorithm, any actor who can derive or guess this secret can generate tokens that the server accepts as legitimate. The predictable nature of the key removes the cryptographic guarantee that JWTs are only issued by the server. Attackers who forge tokens gain the ability to invoke privileged APIs, including those in the OpenAPI security service that permit job creation and execution.
Root Cause
The root cause is a hard-coded or deterministically generated signing key in the DefaultSecretProvider implementation. Administrators who deploy PowerJob using the default configuration inherit this predictable secret. The JwtServiceImpl then signs all issued tokens with that value, so an attacker with knowledge of the codebase can independently produce forged tokens.
Attack Vector
Exploitation requires only network access to a PowerJob Server instance. An unauthenticated attacker reconstructs the predictable signing key from the open-source implementation, then crafts a JWT with administrative claims. The forged token is submitted to authenticated endpoints. Once accepted, the attacker uses PowerJob's job-scheduling APIs to register a task that runs attacker-controlled code, achieving arbitrary code execution on the server. Reference exploitation logic is demonstrated in a public gist.
// No verified exploit code is reproduced here.
// See the linked GitHub gist for a proof-of-concept demonstration.
Detection Methods for CVE-2026-75431
Indicators of Compromise
- Unexpected job or workflow entries created in the PowerJob database that were not registered by legitimate administrators.
- Outbound network connections from the PowerJob Server process to unknown hosts, suggesting attacker-scheduled tasks executing payloads.
- Authentication events for user identities that do not correspond to any provisioned account.
- Child processes such as shells, curl, or wget spawned by the PowerJob JVM process.
Detection Strategies
- Inspect PowerJob application logs for JWT authentication events lacking a preceding login flow.
- Compare deployed values of the JWT signing secret against the default in DefaultSecretProvider to identify vulnerable instances.
- Alert on creation of new PowerJob jobs whose script or command payloads include process-spawning primitives.
- Correlate PowerJob API access with source IP allowlists to surface unauthorized clients.
Monitoring Recommendations
- Forward PowerJob Server logs and JVM process telemetry to a centralized log platform for retention and query.
- Enable network egress monitoring on hosts running PowerJob to detect anomalous outbound traffic.
- Monitor process trees for the PowerJob Java process to identify unexpected child executables.
- Track configuration drift on application-*.properties files, including the daily properties file.
How to Mitigate CVE-2026-75431
Immediate Actions Required
- Replace the default JWT signing secret with a cryptographically random 256-bit value on every PowerJob Server instance.
- Restrict network exposure of PowerJob Server management and OpenAPI endpoints to trusted internal networks only.
- Rotate all existing JWTs and force re-authentication of legitimate users and integrations.
- Audit PowerJob job definitions for entries created outside of change management.
Patch Information
At the time of publication, no vendor advisory or fixed release has been enumerated in the NVD entry. Administrators should monitor the PowerJob GitHub repository for updated releases and configuration guidance. Until a patched release is available, remediation depends on manual replacement of the signing key and network-level hardening.
Workarounds
- Override DefaultSecretProvider with a custom implementation that reads the signing key from a secrets manager or environment variable.
- Place PowerJob Server behind an authenticating reverse proxy or VPN to prevent unauthenticated network reachability.
- Disable the OpenAPI endpoints if they are not required for operations.
- Apply strict firewall rules limiting inbound access to the PowerJob Server port to known worker hosts.
# Configuration example: set a strong JWT secret via environment variable
# and reference it from application.properties instead of using defaults
export POWERJOB_JWT_SECRET="$(openssl rand -base64 48)"
# application.properties
# powerjob.auth.jwt.secret=${POWERJOB_JWT_SECRET}
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.