CVE-2026-9209: mJobTime 15.7.3.32 Unauthenticated SQL Execution RCE via Login.aspx

Published Oct 8, 2026
·
Updated

mJobTime through build 15.7.3.32 contains an unauthenticated SQL execution vulnerability in the Login.aspx admin panel handlers, where the runQueryButton postback and exportSqlQueryServer PageMethod execute caller-supplied SQL against the backing Sybase SQL Anywhere database using DBA/sysadmin privileges with no server-side authentication enforced beyond a client-side sessionStorage flag. Attackers can submit arbitrary SQL through these exposed endpoints to invoke xpcmdshell and xpreadfile, achieving pre-authentication remote code execution as LocalSystem via a single HTTP request.

Affected Software

1 affected component
mJobtime mJobtime<=15.7.3.32

Event History

Oct 8, 2026
CVE Published
via MITRE·03:06 PM
Data Sourced
via MITRE·03:06 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Any reachable mJobTime Login.aspx admin panel on builds through 15.7.3.32 is exposed because the affected handlers do not enforce server-side authentication. An attacker does not need credentials or user interaction.

2

What level of access can an attacker gain?

Caller-supplied SQL is executed with DBA/sysadmin privileges against the Sybase SQL Anywhere database. The described SQL capabilities can be used to achieve remote code execution as LocalSystem.

3

Does the client-side session flag protect the affected endpoints?

No. The only described control is a client-side sessionStorage flag, and the affected handlers have no server-side authentication enforcement.

4

How can I determine whether an installation is affected?

Verify whether the deployment is mJobTime build 15.7.3.32 or earlier and whether its Login.aspx page exposes the runQueryButton postback or exportSqlQuery_Server PageMethod. The vulnerability is reachable through those handlers without server-side authentication.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203