SQL Injection Vulnerability in PowerJob Server by Tech PowerJob
CVE-2026-5736

6.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
7 April 2026

What is CVE-2026-5736?

A critical SQL injection vulnerability has been discovered in the PowerJob Server, specifically within the detailPlus Endpoint in the InstanceController.java file. This vulnerability arises from improper handling of the customQuery argument, allowing an attacker to execute arbitrary SQL commands. The issue affects multiple versions of PowerJob (5.1.0, 5.1.1, 5.1.2) and poses significant risks due to the possibility of remote execution. Despite an early notification regarding this vulnerability, the vendor has yet to address the issue, leaving users susceptible to potential attacks.

Affected Version(s)

PowerJob 5.1.0

PowerJob 5.1.1

PowerJob 5.1.2

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

anch0r (VulDB User)
VulDB CNA Team
.