CVE-2026-5739
Last modified
CVE-2026-5739 is a high-severity vulnerability rated 7.3/10 on the CVSS scale. A security flaw has been discovered in PowerJob 5.1.0/5.1.1/5.1.2. The affected element is the function GroovyEvaluator.evaluate of the file /openApi/addWorkflowNode of the component OpenAPI Endpoint. EPSS estimates a 0.39% chance of exploitation in the next 30 days.
Description
A security flaw has been discovered in PowerJob 5.1.0/5.1.1/5.1.2. The affected element is the function GroovyEvaluator.evaluate of the file /openApi/addWorkflowNode of the component OpenAPI Endpoint. The manipulation of the argument nodeParams results in code injection. The attack can be executed remotely. The project was informed of the problem early through an issue report but has not responded yet.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-5739?
How severe is CVE-2026-5739?
How do I fix CVE-2026-5739?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-57384Subscriber Cross Site Scripting (XSS) in WishList Member X <…6.5
- CVE-2026-57385Improper Neutralization of Special Elements used in an SQL C…8.5
- CVE-2026-57386Incorrect Privilege Assignment vulnerability in Kodezen LLC …8.8
- CVE-2026-57387Improper Neutralization of Input During Web Page Generation …7.1
- CVE-2026-57388Improper Neutralization of Input During Web Page Generation …7.1
- CVE-2026-57389Improper Limitation of a Pathname to a Restricted Directory …8.6
- CVE-2026-57390Missing Authorization vulnerability in EDGARROJAS Extra Prod…6.5
- CVE-2026-57391Improper Neutralization of Input During Web Page Generation …6.5
- CVE-2026-57392Missing Authorization vulnerability in Themefic Tourfic tour…6.5
- CVE-2026-57393Exposure of Sensitive System Information to an Unauthorized …6.5
- CVE-2026-57394Improper Neutralization of Input During Web Page Generation …7.1
- CVE-2026-57395Missing Authorization vulnerability in Themefic Tourfic tour…6.5
Are you affected by CVE-2026-5739?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
