CVE-2026-9209
mJobTime 15.7.3.32 Unauthenticated SQL Execution RCE via Login.aspx
CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th
mJobTime through build 15.7.3.32 contains an unauthenticated SQL execution vulnerability in the Login.aspx admin panel handlers, where the runQueryButton postback and exportSqlQuery_Server PageMethod execute caller-supplied SQL against the backing Sybase SQL Anywhere database using DBA/sysadmin privileges with no server-side authentication enforced beyond a client-side sessionStorage flag. Attackers can submit arbitrary SQL through these exposed endpoints to invoke xp_cmdshell and xp_read_file, achieving pre-authentication remote code execution as LocalSystem via a single HTTP request.
| CWE | CWE-306 CWE-250 |
| Vendor | mjob |
| Product | mjobtime |
| Published | Oct 8, 2026 |
| Last Updated | Oct 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for mjob mjobtime
Be the first to know when new critical vulnerabilities affecting mjob mjobtime are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
mJob / mJobTime
0 โค 15.7.3.32
References
Credits
Nate Fair of Sprocket Security