Skip to main content
Vulnerability Database/CVE-2026-75431

CVE-2026-75431: PowerJob Server RCE Vulnerability

CVE-2026-75431 is a remote code execution flaw in PowerJob Server caused by a predictable JWT signing key in version 5.1.2 and earlier. Attackers can exploit this to execute arbitrary code remotely. This article covers technical details, affected versions, security impact, and mitigation strategies.

Published:

CVE-2026-75431 Overview

CVE-2026-75431 affects PowerJob Server version 5.1.2 and likely earlier releases. The vulnerability stems from the use of a predictable JWT (JSON Web Token) signing key for HS256-based authentication. A remote attacker can forge valid authentication tokens and gain unauthorized access to the server. Successful exploitation allows arbitrary code execution on the PowerJob Server. The flaw is classified under CWE-321: Use of Hard-coded Cryptographic Key.

Critical Impact

Remote unauthenticated attackers can forge JWT tokens using the predictable HS256 signing key, bypass authentication, and execute arbitrary code on affected PowerJob Server instances.

Affected Products

  • PowerJob Server version 5.1.2
  • PowerJob Server versions prior to 5.1.2 (likely affected)
  • Deployments using default configuration from the PowerJob docker-compose file

Discovery Timeline

  • 2026-09-04 - CVE CVE-2026-75431 published to NVD
  • 2026-09-08 - Last updated in NVD database

Technical Details for CVE-2026-75431

Vulnerability Analysis

PowerJob is an open-source distributed task scheduling framework. The server component uses JWT for authentication of administrative and OpenAPI operations. The DefaultSecretProvider implementation supplies a predictable secret used by JwtServiceImpl to sign HS256 tokens. Because HS256 is a symmetric algorithm, any actor who can derive or guess this secret can generate tokens that the server accepts as legitimate. The predictable nature of the key removes the cryptographic guarantee that JWTs are only issued by the server. Attackers who forge tokens gain the ability to invoke privileged APIs, including those in the OpenAPI security service that permit job creation and execution.

Root Cause

The root cause is a hard-coded or deterministically generated signing key in the DefaultSecretProvider implementation. Administrators who deploy PowerJob using the default configuration inherit this predictable secret. The JwtServiceImpl then signs all issued tokens with that value, so an attacker with knowledge of the codebase can independently produce forged tokens.

Attack Vector

Exploitation requires only network access to a PowerJob Server instance. An unauthenticated attacker reconstructs the predictable signing key from the open-source implementation, then crafts a JWT with administrative claims. The forged token is submitted to authenticated endpoints. Once accepted, the attacker uses PowerJob's job-scheduling APIs to register a task that runs attacker-controlled code, achieving arbitrary code execution on the server. Reference exploitation logic is demonstrated in a public gist.

// No verified exploit code is reproduced here.
// See the linked GitHub gist for a proof-of-concept demonstration.

Detection Methods for CVE-2026-75431

Indicators of Compromise

  • Unexpected job or workflow entries created in the PowerJob database that were not registered by legitimate administrators.
  • Outbound network connections from the PowerJob Server process to unknown hosts, suggesting attacker-scheduled tasks executing payloads.
  • Authentication events for user identities that do not correspond to any provisioned account.
  • Child processes such as shells, curl, or wget spawned by the PowerJob JVM process.

Detection Strategies

  • Inspect PowerJob application logs for JWT authentication events lacking a preceding login flow.
  • Compare deployed values of the JWT signing secret against the default in DefaultSecretProvider to identify vulnerable instances.
  • Alert on creation of new PowerJob jobs whose script or command payloads include process-spawning primitives.
  • Correlate PowerJob API access with source IP allowlists to surface unauthorized clients.

Monitoring Recommendations

  • Forward PowerJob Server logs and JVM process telemetry to a centralized log platform for retention and query.
  • Enable network egress monitoring on hosts running PowerJob to detect anomalous outbound traffic.
  • Monitor process trees for the PowerJob Java process to identify unexpected child executables.
  • Track configuration drift on application-*.properties files, including the daily properties file.

How to Mitigate CVE-2026-75431

Immediate Actions Required

  • Replace the default JWT signing secret with a cryptographically random 256-bit value on every PowerJob Server instance.
  • Restrict network exposure of PowerJob Server management and OpenAPI endpoints to trusted internal networks only.
  • Rotate all existing JWTs and force re-authentication of legitimate users and integrations.
  • Audit PowerJob job definitions for entries created outside of change management.

Patch Information

At the time of publication, no vendor advisory or fixed release has been enumerated in the NVD entry. Administrators should monitor the PowerJob GitHub repository for updated releases and configuration guidance. Until a patched release is available, remediation depends on manual replacement of the signing key and network-level hardening.

Workarounds

  • Override DefaultSecretProvider with a custom implementation that reads the signing key from a secrets manager or environment variable.
  • Place PowerJob Server behind an authenticating reverse proxy or VPN to prevent unauthenticated network reachability.
  • Disable the OpenAPI endpoints if they are not required for operations.
  • Apply strict firewall rules limiting inbound access to the PowerJob Server port to known worker hosts.
bash
# Configuration example: set a strong JWT secret via environment variable
# and reference it from application.properties instead of using defaults
export POWERJOB_JWT_SECRET="$(openssl rand -base64 48)"

# application.properties
# powerjob.auth.jwt.secret=${POWERJOB_JWT_SECRET}

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.