External risk intelligence

PowerJob Unauthenticated Remote Code Execution in Server-Worker Transport Layer.

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-75429

The vulnerability exists in the Server-Worker transport layer of a job scheduling system. While this communication typically occurs within an internal cluster or private network segment to facilitate task coordination, it is occasionally exposed to broader network segments depending on the specific infrastructure deployment, making internet reachability possible but not a standard design pattern.

Authentication Bypass

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory addresses a critical vulnerability found in PowerJob, a job scheduling system. The flaw allows for unauthenticated remote code execution, meaning an attacker could potentially run commands on the affected system without needing any credentials. The primary concern is to confirm if PowerJob is deployed in a manner that exposes this vulnerable component to potential attackers.

  • Flaw allows remote code execution on job scheduling systems.
  • Unauthenticated access could lead to significant compromise.
  • Confirm if this scheduling software is deployed externally.

Attack Path

How an attacker could exploit the issue

An attacker could reach the vulnerable component by sending a request to the `/friend/process` endpoint over the network. This endpoint is part of the communication layer between the PowerJob server and its workers. If this communication is exposed to the internet, an unauthenticated attacker could exploit this vulnerability to execute arbitrary code on the server.

  • Network access to the endpoint.
  • Sending a request to `/friend/process`.
  • Remote code execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability in PowerJob's Server-Worker transport layer could allow an unauthenticated attacker to execute arbitrary code remotely. This could occur when the affected endpoint is accessible over the network.

  • Arbitrary code execution on the server.
  • Unauthenticated network access to endpoint.
  • Compromise of system and its scheduled tasks.

Operational Fix

Recommended remediation, mitigation, and detection steps

Real-world action for this PowerJob vulnerability likely falls to the platform or infrastructure team responsible for the job scheduling system, with input from the application owners who rely on it. The first practical step is to confirm where PowerJob is deployed, assess its network exposure and business criticality, identify the accountable owner, and then plan remediation based on that risk.

  • Platform or app owner issues.
  • Verify network exposure and criticality.
  • Plan risk-based remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is PowerJob?

PowerJob is an open-source distributed job scheduling system. Developers use it to automate and manage complex background tasks and workflows across large-scale clusters, coordinating execution between central servers and worker nodes to keep applications running efficiently.

What does CVE-2026-75429 mean for system security?

This CVE represents an Improper Authentication vulnerability (CWE-287). It means the system fails to verify the identity of someone connecting to it. Because of this, an attacker can bypass login requirements to perform unauthorized actions, specifically executing commands remotely on the server.

How can an attacker trigger this vulnerability?

An attacker triggers this by sending a specially crafted request to the /friend/process endpoint. This endpoint resides within the transport layer that servers and workers use to communicate. Requests sent to unrelated endpoints or through secured, non-public network channels will not trigger this specific flaw.

Who should be concerned about this vulnerability?

Organizations using PowerJob should care, especially if their infrastructure allows network access to the server-worker transport layer. According to Halo Surface Signal, while this communication is typically restricted to private networks, deployment configurations sometimes inadvertently expose these endpoints to broader, internet-facing segments.

What is the first step to address this risk?

Begin by identifying all PowerJob instances within your environment and mapping their network reachability. Determine if the Server-Worker transport layer is accessible from outside your internal network, then consult with your platform or infrastructure team to restrict access and coordinate further risk-based remediation.

References