CVE-2026-75430
48Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 9.8epss 0.9%
from disclosure to weapon0 days
Published on NVDSep 4
1st PoCAug 10
exploitation probability
0.9%top 43% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
PowerJob Worker version 5.1.2 (and likely earlier versions) exposes the /worker/deployContainer HTTP endpoint without authentication on the default transport port. This allows a remote attacker to execute arbitrary code.
CVSS:3.1/AC:L/AV:N/A:H/C:H/I:H/PR:N/S:U/UI:N
Affected products
n/a · n/apublic PoCs found — 1
githubgithub.com/unpredictable21/CVE-2026-75430_PowerJob_worker_deployContainer_RCE★ 0⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
https://gist.github.com/unpredictable21/fcb62d394db30525412c4b5b1efd0233https://github.com/PowerJob/PowerJobhttps://github.com/PowerJob/PowerJob/blob/master/powerjob-worker/src/main/java/tech/powerjob/worker/actors/WorkerActor.javahttps://github.com/PowerJob/PowerJob/blob/master/powerjob-worker/src/main/java/tech/powerjob/worker/container/OmsContainerFactory.javahttps://github.com/PowerJob/PowerJob/blob/master/SECURITY.md