S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 21, 2026

CVE-2025-11580 Scanner

CVE-2025-11580 Scanner - Authorization Bypass vulnerability in PowerJob

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.3k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-11580
5.5
CVSSmedium
Exploitable remotely over the internet · no authentication required.

A weakness has been identified in PowerJob up to 5.1.2. This affects the function list of the file /user/list. This manipulation causes missing authorization. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
PowerJobby n/a
5.1.0
Updated Aug 22, 2026View on NVD →
Detail

PowerJob is a widely-used job scheduling platform that enables users to achieve distributed tasks processing effectively. It is commonly implemented in enterprises to manage scheduled processes and automate workflows by IT professionals. This platform serves as a tool for enhancing operational efficiency and streamlining task management within organizational processes. IT administrators and developers utilize it to create, manage, and execute scheduled tasks across varied environments. PowerJob is appreciated for its ability to handle a large number of concurrent processes, making it a significant player in distributed job scheduling. Its usage spans sectors intending to improve operational workflows and task automation capabilities.

The authorization bypass vulnerability detected in PowerJob 5.1.2 refers to a loophole where unauthorized users can access specific resources or functions without proper authorization checks. This vulnerability is typically the result of an oversight in access control mechanisms, failing to verify users' credentials adequately before granting access. Such vulnerabilities can pose substantial risks, potentially leading to unauthorized data access and even privilege escalation. The identified flaw allows remote, unauthenticated attackers to exploit this gap, potentially accessing privileged information. Vigilant security measures and updates are crucial to prevent exploitation of these vulnerabilities. It's essential for users to be aware of the existing security flaws and take necessary precautions.

The technical details of this vulnerability in PowerJob involve exploiting the /user/list endpoint. An unauthenticated attacker sends a GET request to this vulnerable endpoint without needing valid credentials. The lack of proper authorization checks allows the attacker to receive a successful response indicating the bypass. The response contains data typically restricted to authorized users, such as user account details. As a result, attackers gain unauthorized access to sensitive information, which can further be used maliciously. Monitoring and securing these endpoints is crucial to avoid unauthorized access in systems.

Exploiting this authorization bypass vulnerability can lead to severe consequences including data exposure and privilege escalation. Unauthorized users gaining access to restricted resources may use this information to infiltrate deeper into systems. Sensitive data, user details, and potentially confidential information might fall into malicious actors' hands. Furthermore, this breach can pave the way for subsequent attacks, expanding the risk footprint for affected organizations. Any data exfiltrated unlawfully can lead to reputational damage and financial losses for the entity involved. Such vulnerabilities warrant immediate attention and rectification to shield against potential security threats.

REFERENCES

Solution Advice
  • Update PowerJob to a version beyond 5.1.2 to secure against the identified vulnerabilities.
  • Implement proper access control mechanisms to ensure each endpoint verifies user credentials adequately.
  • Regularly review and audit access logs to detect unauthorized access attempts on the system.
  • Deploy additional layers of security such as multi-factor authentication to enhance system protection.
  • Stay informed about potential vulnerabilities and apply security patches from trusted sources promptly.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.