---
id: CVE-2026-9209
title: >-
  mJobTime through build 15.7.3.32 contains an unauthenticated SQL execution
  vulnerability in the Login.aspx admin panel handlers, where the runQueryButton
  postback and exportSqlQuery_Server PageMethod execute caller-supplied SQL
  against t…
summary: >-
  mJobTime through build 15.7.3.32 contains an unauthenticated SQL execution
  vulnerability in the Login.aspx admin panel handlers, where the runQueryButton
  postback and exportSqlQuery_Server PageMethod execute caller-supplied SQL
  against t…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-250
  - CWE-306
vendor: mJob
product: mJobTime
affected:
  - mJobTime <= 15.7.3.32
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T21:35:53.890'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-9209'
references:
  - url: 'https://mjobtime.com/'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.sprocketsecurity.com/blog/cve-2026-9209-pre-authentication-sql-injection-to-remote-code-execution-in-mjobtime
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/mjobtime-unauthenticated-sql-execution-rce-via-login-aspx
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-10-08T15:35:27.860447Z'
ingestedAt: '2026-10-08T15:49:37.994Z'
---

## Overview

mJobTime through build 15.7.3.32 contains an unauthenticated SQL execution vulnerability in the Login.aspx admin panel handlers, where the runQueryButton postback and exportSqlQuery_Server PageMethod execute caller-supplied SQL against the backing Sybase SQL Anywhere database using DBA/sysadmin privileges with no server-side authentication enforced beyond a client-side sessionStorage flag. Attackers can submit arbitrary SQL through these exposed endpoints to invoke xp_cmdshell and xp_read_file, achieving pre-authentication remote code execution as LocalSystem via a single HTTP request.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
