CVE-2026-75429

PowerJob versions 4.x through 5.1.2 contain an unauthenticated remote code execution vulnerability in the /friend/process endpoint of the Server-Worker transport layer

  • Published Sep 4, 2026
  • CVSS 9.8 critical
  • 1.0% chance of exploitation in the next 30 days (EPSS)

CVE-2026-75429 at the National Vulnerability Database