important · RCE — Job scheduling
PowerJob's unauthenticated server and worker transports expose two direct paths to code execution.
Affects
PowerJob, a Java distributed job-scheduling and computing framework whose server and worker components commonly run in containers on Linux.
The server turns a selected Spring bean method into Groovy evaluation, while the worker downloads an attacker-selected JAR and initializes its Spring context.
Detail and 6 sources
Public exploits demonstrate execution, and no maintainer fix is established.
Sources
ResearchCVE-2026-75429 - Vulnerability Details - OpenCVEResearchCVE-2026-75430 - Vulnerability Details - OpenCVECode / PoCGitHub - unpredictable21/CVE-2026-75429_PowerJob_friend_process_RCE · GitHubCode / PoCGitHub - unpredictable21/CVE-2026-75430_PowerJob_worker_deployContainer_RCE · GitHubCode / PoCPowerJob/powerjob-worker/src/main/java/tech/powerjob/worker/actors/WorkerActor.java at master · PowerJob/PowerJob · GitHubCode / PoCPowerJob/powerjob-worker/src/main/java/tech/powerjob/worker/container/OmsContainerFactory.java at master · PowerJob/PowerJob · GitHub