SQL Injection Vulnerability in PowerJob Server by Tech PowerJob
CVE-2026-5736
6.9MEDIUM
What is CVE-2026-5736?
A critical SQL injection vulnerability has been discovered in the PowerJob Server, specifically within the detailPlus Endpoint in the InstanceController.java file. This vulnerability arises from improper handling of the customQuery argument, allowing an attacker to execute arbitrary SQL commands. The issue affects multiple versions of PowerJob (5.1.0, 5.1.1, 5.1.2) and poses significant risks due to the possibility of remote execution. Despite an early notification regarding this vulnerability, the vendor has yet to address the issue, leaving users susceptible to potential attacks.
Affected Version(s)
PowerJob 5.1.0
PowerJob 5.1.1
PowerJob 5.1.2
