VULNERABILITY OVERVIEW CVE-2026-5739 is a code injection vulnerability affecting PowerJob versions 5.1.0, 5.1.1, and 5.1.2. The flaw exists in the GroovyEvaluator.evaluate function within the OpenAPI endpoint component /openApi/addWorkflowNode, where insufficient input validation on the nodeParams argument allows attackers to inject arbitrary code. SEVERITY ASSESSMENT The vulnerability carries a CVSS v3.1 score of 7.3 (HIGH) with a network-based attack vector requiring no authentication, low complexity, and no user interaction. The attack can be executed remotely and results in partial compromise of confidentiality, integrity, and availability. The EPSS score of 0.000610000 indicates minimal current exploitation activity relative to the broader CVE landscape. EXPLOITATION STATUS There is no evidence of active exploitation in public datasets, and the vulnerability is not listed on CISA's Known Exploited Vulnerabilities catalog. No public exploit code is currently known to be available. Community engagement appears minimal, as the development team has not responded to the early disclosure notification, suggesting limited awareness or prioritization of the issue within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| N/A | PowerJob | 5.1.0, 5.1.1, 5.1.2CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.