Executive brief
PowerJob is an enterprise job scheduling middleware used for distributed computing. A vulnerability in the transport endpoint allows unauthenticated attackers to perform server-side request forgery (SSRF) attacks, potentially enabling them to access internal resources, bypass network controls, or pivot to other systems.
Technical details
A server-side request forgery (SSRF) vulnerability exists in the MuConnectionManager.getOrCreateConnection() function within PowerJob's TestController transport endpoint. The vulnerability is unauthenticated and network-accessible, allowing remote attackers to forge requests to internal services without requiring authentication or special privileges. The manipulation of the affected function enables attackers to make arbitrary outbound requests from the server, potentially accessing internal APIs, metadata services, or other network resources. A public exploit is available, and patches have been discussed but not yet released by the project.
Affected products
- PowerJob PowerJob up to 5.1.2
Timeline
- 2026-08-31: disclosed