Impact
PowerJob versions 4.x through 5.1.2 expose an unauthenticated Remote Code Execution vulnerability in the Server-Worker /friend/process endpoint. The flaw allows an attacker to send a specially crafted request without authentication and execute arbitrary commands on the host, thereby compromising confidentiality, integrity, and availability of the affected systems.
Affected Systems
The affected component is the PowerJob Server‑Worker service running any 4.x or 5.1.2 release. Hosts that expose the /friend/process endpoint are vulnerable, regardless of deployment format.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity, and while the EPSS is less than 1% indicating a low current exploitation probability, the unauthenticated nature of the RCE elevates the threat posture. The issue is not listed in the CISA KEV catalog, so no public exploits are known, but an attacker could reach the endpoint over the network and achieve full compromise if no additional controls are in place.
OpenCVE Enrichment