Description
Polyaxon through 2.16.4 renders operation specification fields with an unsandboxed Jinja2 environment during server-side run preparation, allowing authenticated users to execute arbitrary code. Attackers can submit runs with Jinja2 payloads in queue, namespace, conditions, presets, or dependencies fields to execute operating system commands in the scheduler process context, exposing database credentials and service tokens.
Published: 2026-09-15
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch Immediately
AI Analysis

Impact

Polyaxon versions up to 2.16.4 render operation specification fields with an unsandboxed Jinja2 environment during server‑side run preparation. This flaw allows authenticated users to inject Jinja2 expressions that are evaluated in the scheduler process context, giving an attacker the ability to run arbitrary operating system commands. The attack can exploit fields such as queue, namespace, conditions, presets, or dependencies, potentially exposing database credentials and service tokens.

Affected Systems

All deployments of Polyaxon using versions 2.16.4 or earlier are affected. The vulnerability impacts the server component that prepares jobs for execution, and any authenticated user who can submit runs can exploit this flaw.

Risk and Exploitability

The vulnerability carries a CVSS score of 8.7, indicating high severity. Exploitation requires authentication and access to the Polyaxon server, so the risk is primarily to internal users or compromised accounts. The EPSS score of 0.00476 indicates a very low probability of exploitation in the current state, though the flaw is not listed in the CISA KEV catalog. Nevertheless, the high CVSS score and the ability to execute code in the scheduler process represent a serious internal threat.

Generated by OpenCVE AI on September 17, 2026 at 17:33 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Polyaxon to version 2.16.5 or later, which removes the unsandboxed Jinja2 engine from the run preparation process.
  • Restrict job creation permissions to only trusted users and disable the ability to include Jinja2 expressions in operation specifications; configure role‑based access controls accordingly.
  • Apply network segmentation or firewall controls to isolate the Polyaxon scheduler from untrusted networks, and enable detailed logging or monitoring for anomalous Jinja2 payloads in job definitions.

Generated by OpenCVE AI on September 17, 2026 at 17:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Polyaxon
Polyaxon polyaxon
Vendors & Products Polyaxon
Polyaxon polyaxon

Tue, 15 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
Description Polyaxon through 2.16.4 renders operation specification fields with an unsandboxed Jinja2 environment during server-side run preparation, allowing authenticated users to execute arbitrary code. Attackers can submit runs with Jinja2 payloads in queue, namespace, conditions, presets, or dependencies fields to execute operating system commands in the scheduler process context, exposing database credentials and service tokens.
Title Polyaxon through 2.16.4 Server-Side Template Injection via Unsandboxed Jinja2 Engine
Weaknesses CWE-1336
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Polyaxon Polyaxon
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:22:30.764Z

Reserved: 2026-09-15T10:42:44.369Z

Link: CVE-2026-91925

cve-icon Vulnrichment

Updated: 2026-09-15T12:16:18.639Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T11:17:13.220

Modified: 2026-09-24T20:43:32.537

Link: CVE-2026-91925

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:15:13Z

Weaknesses
  • CWE-1336

    Improper Neutralization of Special Elements Used in a Template Engine