CVE-2026-9209: mJobTime 15.7.3.32 Unauthenticated SQL Execution RCE via Login.aspx
mJobTime through build 15.7.3.32 contains an unauthenticated SQL execution vulnerability in the Login.aspx admin panel handlers, where the runQueryButton postback and exportSqlQueryServer PageMethod execute caller-supplied SQL against the backing Sybase SQL Anywhere database using DBA/sysadmin privileges with no server-side authentication enforced beyond a client-side sessionStorage flag. Attackers can submit arbitrary SQL through these exposed endpoints to invoke xpcmdshell and xpreadfile, achieving pre-authentication remote code execution as LocalSystem via a single HTTP request.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Any reachable mJobTime Login.aspx admin panel on builds through 15.7.3.32 is exposed because the affected handlers do not enforce server-side authentication. An attacker does not need credentials or user interaction.
What level of access can an attacker gain?
Caller-supplied SQL is executed with DBA/sysadmin privileges against the Sybase SQL Anywhere database. The described SQL capabilities can be used to achieve remote code execution as LocalSystem.
Does the client-side session flag protect the affected endpoints?
No. The only described control is a client-side sessionStorage flag, and the affected handlers have no server-side authentication enforcement.
How can I determine whether an installation is affected?
Verify whether the deployment is mJobTime build 15.7.3.32 or earlier and whether its Login.aspx page exposes the runQueryButton postback or exportSqlQuery_Server PageMethod. The vulnerability is reachable through those handlers without server-side authentication.