Junglewise Threat Intelligence

CVE-2026-5739: PowerJob Groovy code injection in OpenAPI Endpoint

CVE-2026-5739 · Severity: high · CVSS 7.3 · Published 2026-04-07

Technologies: PowerJob, tech.powerjob:powerjob-server-starter (Maven). Vendors: PowerJob, Maven.

Executive brief

PowerJob, an enterprise job scheduling middleware, contains a security flaw that allows remote attackers to execute arbitrary code on the server. By sending specially crafted requests to the system's open API, an attacker can bypass authentication and run malicious scripts. This could lead to a complete takeover of the server, unauthorized access to sensitive data, and disruption of scheduled business operations.

Technical details

A remote code execution (RCE) vulnerability exists in PowerJob versions 5.1.0, 5.1.1, and 5.1.2 due to a combination of two flaws. First, the OpenAPI endpoint (/openApi/*) is unauthenticated by default because the 'oms.auth.openapi.enable' configuration defaults to false. Second, the 'GroovyEvaluator.evaluate' function lacks a sandbox, using 'ScriptEngine.eval()' to process the 'nodeParams' argument from 'addWorkflowNode' requests. An attacker can chain these flaws by creating a workflow with a 'DECISION' node containing a malicious Groovy script and then triggering that workflow via 'runWorkflow'. This results in arbitrary code execution within the Server JVM context. As of the advisory date, no official patch has been released, though workarounds include enabling OpenAPI authentication and implementing Groovy sandboxing.

Affected products

  • PowerJob PowerJob 5.1.0, 5.1.1, 5.1.2

Timeline

  • 2026-03-24: disclosed: Issue reported on GitHub repository
  • 2026-04-07: advisory: VulDB and NVD publication

References

Related threats