PowerJob Worker version 5.1.2 and likely earlier versions contain a critical unauthenticated remote code execution vulnerability. The /worker/deployContainer HTTP endpoint is exposed without any authentication on the default transport port. A remote attacker can exploit this endpoint to execute arbitrary code on the affected system. The vulnerability requires no credentials or special privileges to exploit. The issue resides in the WorkerActor and OmsContainerFactory components of the powerjob-worker module. This represents a critical security risk for any deployment of PowerJob Worker that is network-accessible. Users are advised to review the SECURITY.md guidance provided by the PowerJob project. The vulnerability has been assigned CVE-2026-75430 and is tracked in the NVD.