Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-9wq6-87hw-6mhc | PowerJob OpenAPIController is missing authorization |
Tue, 24 Feb 2026 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 27 Oct 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:powerjob:powerjob:*:*:*:*:*:*:*:* |
Mon, 20 Oct 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Powerjob
Powerjob powerjob |
|
| Vendors & Products |
Powerjob
Powerjob powerjob |
Fri, 10 Oct 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 10 Oct 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security vulnerability has been detected in PowerJob up to 5.1.2. This vulnerability affects unknown code of the file /openApi/runJob of the component OpenAPIController. Such manipulation leads to missing authorization. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. | |
| Title | PowerJob OpenAPIController runJob authorization | |
| Weaknesses | CWE-862 CWE-863 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-02-24T06:57:11.124Z
Reserved: 2025-10-10T11:42:19.026Z
Link: CVE-2025-11581
Updated: 2025-10-10T19:15:41.613Z
Status : Modified
Published: 2025-10-10T19:15:36.960
Modified: 2026-02-24T08:16:14.697
Link: CVE-2025-11581
No data.
OpenCVE Enrichment
Updated: 2025-10-20T16:17:15Z
Github GHSA