PT-2026-30979 · Powerjob · Powerjob

Anch0R

·

Published

2026-04-07

·

Updated

2026-04-07

·

CVE-2026-5736

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PowerJob versions 5.1.0 through 5.1.2
Description A SQL injection issue exists due to the manipulation of the customQuery argument within an unknown function in the file powerjob-server/powerjob-server-starter/src/main/java/tech/powerjob/server/web/controller/InstanceController.java of the detailPlus endpoint. Remote exploitation is possible.
Recommendations Update to a newer version that contains a fix for this vulnerability.

Fix

SQL injection

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2026-5736
GHSA-4FP2-3XGG-JG4W

Affected Products

Powerjob