{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/powerjob--5.1.2/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:powerjob:powerjob:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-82630"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["PowerJob (\u003c= 5.1.2)"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","ssrf","remote-execution"],"_cs_type":"advisory","_cs_vendors":["PowerJob"],"content_html":"\u003cp\u003eA server-side request forgery (SSRF) vulnerability, assigned CVE-2026-82630, exists in PowerJob versions up to and including 5.1.2. The flaw is located in the \u003ccode\u003eMuConnectionManager.getOrCreateConnection\u003c/code\u003e function within the \u003ccode\u003eTestController.java\u003c/code\u003e file of the transport endpoint component. This vulnerability allows an unauthenticated remote attacker to manipulate network connections and force the PowerJob server to perform requests to internal or external network resources. Given the availability of public exploit material, there is a risk of unauthorized data access or interaction with internal services hosted within the same network as the PowerJob instance. The project maintainers have not yet provided a patch or formal response to the reported issue.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows remote attackers to perform SSRF attacks, potentially leading to unauthorized access to internal services, metadata services, or sensitive data within the server's network perimeter. The scope of impact depends on the internal network architecture of the affected organization.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor webserver access logs for anomalous requests to the \u003ccode\u003eTestController\u003c/code\u003e endpoint that deviate from baseline traffic patterns.\u003c/li\u003e\n\u003cli\u003eImplement strict network egress filtering on the host running the PowerJob server to prevent unauthorized internal scanning or data exfiltration via SSRF.\u003c/li\u003e\n\u003cli\u003eEvaluate the necessity of exposing the PowerJob instance to untrusted networks; restrict access using VPN or firewall rules until a security update is released.\u003c/li\u003e\n\u003cli\u003eMonitor for any evidence of unauthorized requests sourced from the PowerJob server internal network segment.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-31T09:16:28Z","date_published":"2026-08-31T09:16:28Z","id":"https://feed.craftedsignal.io/briefs/2026-08-powerjob-ssrf/","summary":"PowerJob versions up to 5.1.2 contain a server-side request forgery vulnerability in the MuConnectionManager component that allows remote, unauthenticated attackers to perform unauthorized network requests.","title":"SSRF Vulnerability in PowerJob Transport Endpoint","url":"https://feed.craftedsignal.io/briefs/2026-08-powerjob-ssrf/"}],"language":"en","title":"CraftedSignal Threat Feed - PowerJob (\u003c= 5.1.2)","version":"https://jsonfeed.org/version/1.1"}