SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-75431

CRITICAL · CVSS 9.1 EPSS 0.77% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

PowerJob Server versions 5.1.2 and earlier utilize a predictable JWT signing key for HS256-based authentication, making them susceptible to remote code execution by attackers. Organizations using these versions should prioritize patching or upgrading their systems to mitigate the risk of exploitation. This vulnerability poses a critical threat to the integrity and security of affected environments.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-75431
Severity
CRITICAL
CVSS
9.1
EPSS
0.77%

Original NVD Description

PowerJob Server version 5.1.2 (and likely earlier) uses a predictable JWT signing key for HS256-based authentication. This allows a remote attacker to execute arbitrary code.