Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-75431: PowerJob Server lets attackers run code via weak token key
CVE-2026-75431 · published today
Summary
The PowerJob Server (version 5.1.2 and earlier) uses a signing key that can be guessed, allowing unauthorized users to create valid authentication tokens. This lets a remote attacker execute any command on the server. Update to a newer version or change the signing key to a strong, random value as soon as possible.
Original advisory text
PowerJob Server version 5.1.2 (and likely earlier) uses a predictable JWT signing key for HS256-based authentication. This allows a remote attacker to execute arbitrary code.
PowerJob Server version 5.1.2 (and likely earlier) uses a predictable JWT signing key for HS256-based authentication. This allows a remote attacker to execute arbitrary code.
References
- https://github.com/PowerJob/PowerJob/blob/master/docker-compose.yml
- https://github.com/PowerJob/PowerJob/blob/master/powerjob-server/powerjob-server...
- https://github.com/PowerJob/PowerJob/blob/master/powerjob-server/powerjob-server...
- https://gist.github.com/unpredictable21/39e6ce22e4bc45b0e553d0fa6a6e4d1c
- https://github.com/PowerJob/PowerJob/blob/master/powerjob-server/powerjob-server...
- https://github.com/PowerJob/PowerJob/blob/master/powerjob-server/powerjob-server...
Severity
9.1
Critical
CVSS 3.1: 9.1 (MITRE)
Type
CWE-321Use of Hard-coded Cryptographic Key
Timeline
Published4 Sep 2026
Updated4 Sep 2026
First seen4 Sep 2026
Monitor software like this
Free during beta