Skip to finding
important · RCE — Job scheduling

PowerJob's unauthenticated server and worker transports expose two direct paths to code execution.

Affects

PowerJob, a Java distributed job-scheduling and computing framework whose server and worker components commonly run in containers on Linux.

The server turns a selected Spring bean method into Groovy evaluation, while the worker downloads an attacker-selected JAR and initializes its Spring context.

Detail and 6 sources
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Saturday, September 5, 2026