VYPR
Critical severityNVD Advisory· Published Apr 20, 2023· Updated Feb 5, 2025

CVE-2023-29926

CVE-2023-29926

Description

PowerJob V4.3.2 contains an unauthorized interface that allows remote code execution, enabling unauthenticated attackers to execute arbitrary commands.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

PowerJob V4.3.2 contains an unauthorized interface that allows remote code execution, enabling unauthenticated attackers to execute arbitrary commands.

Vulnerability

Overview

PowerJob V4.3.2, an open-source distributed job scheduling framework, is vulnerable to remote code execution due to an unauthorized interface. The interface lacks proper authentication checks, allowing attackers to invoke it without any credentials [1].

Exploitation

An attacker can exploit this vulnerability by sending specially crafted HTTP requests to the exposed interface. No authentication or prior access is required, making it exploitable from any network reachable position [2]. The exact interface and request parameters are detailed in the NVD reference [2].

Impact

Successful exploitation grants the attacker arbitrary code execution on the PowerJob server. This can lead to full control over the application, data exfiltration, and lateral movement within the infrastructure [2].

Mitigation

As of the CVE publication date (April 2023), no official patch was available. Users are advised to restrict network access to the PowerJob server and monitor for vendor updates [2]. The project maintainers should be contacted for remediation guidance.

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
tech.powerjob:powerjobMaven
<= 4.3.2

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.