← Back to overview

A Server-Side Request Forgery (SSRF) vulnerability was identified in PowerJob up to version 5.1.2. The vulnerability exists in the MuConnectionManager.getOrCreateConnection function within the TestController.java file of the Transport Endpoint component. An attacker can exploit this vulnerability remotely without authentication. A public exploit is already available, increasing the risk of active exploitation. The project was notified via an issue report but has not yet responded or released a patch. The vulnerability affects the powerjob-server-starter module of the PowerJob server. Organizations running PowerJob up to version 5.1.2 are advised to assess their exposure and implement mitigations as the vendor has not addressed the issue.

Affected products

  • PowerJob up to 5.1.2

Related CVE's

  • CVE-2026-82630

Categories

  • Enterprise Applications
  • Web Technologies