CVE-2026-75429
PowerJob versions 4.x through 5.1.2 contain an unauthenticated remote code execution vulnerability in the /friend/process endpoint of the Server-Worker transport layer
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://gist.github.com/unpredictable21/dbd1791294c9a77ad0ee3d4827073966, https://github.com/PowerJob/PowerJob/blob/master/docker-compose.yml, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/75xxx/CVE-2026-75429.json, https://nvd.nist.gov/vuln/detail/CVE-2026-75429, https://github.com/PowerJob/PowerJob, https://github.com/unpredictable21/CVE-2026-75429PowerJobfriendprocessRCE