Junglewise Threat Intelligence

CVE-2026-75431: PowerJob Server predictable JWT signing key in HS256 authentication

CVE-2026-75431 · Severity: critical · CVSS 9.1 · Published 2026-09-04

Vendors: PowerJob.

Executive brief

PowerJob Server is a distributed job scheduling platform used to manage and execute scheduled tasks. The system uses a hardcoded or predictable JWT signing key for authentication, allowing remote attackers to forge authentication tokens and gain administrative access without valid credentials. This enables complete system compromise, including arbitrary code execution on the server.

Technical details

The vulnerability exists in PowerJob Server's JWT authentication implementation (DefaultSecretProvider.java, JwtServiceImpl.java) which uses a predictable HMAC-SHA256 (HS256) signing key derived from a common database connection string. An attacker can offline compute the key using the default JDBC URL and forge valid admin tokens for any account, bypassing authentication entirely. No user interaction or prior authentication is required; the attack is purely network-based and affects default configurations. The PoC demonstrates successful token forgery that passes authentication on protected endpoints such as /namespace/list. Additionally, a separate OpenAPI token forgery vulnerability exists independently of admin password changes, further expanding the attack surface. No patch information is currently available from the advisory.

Affected products

  • PowerJob PowerJob Server 5.1.2 and likely earlier

Timeline

  • 2026-09-04: disclosed
  • other: PoC code published on GitHub

References

Related threats