PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-9209 mJob CVE debrief

A critical vulnerability exists in mJobTime 15.7.3.32, allowing unauthenticated SQL execution via the Login.aspx admin panel. This issue enables attackers to execute arbitrary SQL, invoke xp_cmdshell and xp_read_file, and achieve pre-authentication remote code execution as LocalSystem via a single HTTP request. The vulnerability is confirmed in mJobTime 15.7.3.32 and defenders should assess exposure and prioritize patching or mitigation. The vulnerability exists in the Login.aspx admin panel handlers of mJobTime 15.7.3.32, where the runQueryButton postback and exportSqlQuery_Server PageMethod execute caller-supplied SQL against the Sybase SQL Anywhere database with DBA/sysadmin  

Vendor
mJob
Product
mJobTime
CVSS
CRITICAL 9.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-08
Advisory published
2026-10-08
Advisory updated
2026-10-08

Who should care

Defenders and administrators of mJobTime 15.7.3.32 should assess exposure and prioritize patching or mitigation to prevent potential disruption and unauthorized access. The vulnerability is confirmed in mJobTime 15.7.3.32 and defenders should assess exposure and prioritize patching or mitigation. The issue enables attackers to execute arbitrary SQL, invoke xp_cmdshell and xp_read_file, and achieve pre-authentication remote code execution as LocalSystem via

Why it matters

CVE-2026-9209 is a critical vulnerability in mJobTime 15.7.3.32 that allows unauthenticated SQL execution and remote code execution. Defenders should prioritize patching or mitigation to prevent potential disruption and unauthorized access.

  • Potential for pre-authentication remote code execution as LocalSystem
  • Unauthenticated SQL execution via exposed endpoints
  • Invocation of xp_cmdshell and xp_read_file
  • Possible disruption of critical business operations

Technical summary

The vulnerability exists in the Login.aspx admin panel handlers of mJobTime 15.7.3.32, where the runQueryButton postback and exportSqlQuery_Server PageMethod execute caller-supplied SQL against the Sybase SQL Anywhere database with DBA/sysadmin privileges, without server-side authentication. Attackers can submit arbitrary SQL through these exposed endpoints to invoke xp_cmdshell and xp_read_file, achieving pre-authentication remote code execution as LocalSystem via a single HTTP request. The vulnerability is confirmed in mJobTime 15.7.3.32 and defenders should assess exposure and prioritize patching or mitigation.

Defensive priority

High priority for immediate patching or mitigation

Recommended defensive actions

  • Immediately patch or update mJobTime to a version beyond 15.7.3.32
  • Implement Web Application Firewall (WAF) rules to detect and block suspicious SQL queries
  • Conduct thorough inventory checks to identify and mitigate exposure
  • Monitor for unusual activity or exploitation attempts
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The vulnerability is confirmed in mJobTime 15.7.3.32. Official sources and references provide details on the unauthenticated SQL execution vulnerability. The issue enables attackers to execute arbitrary SQL, invoke xp_cmdshell and xp_read_file, and achieve pre-authentication remote code execution as LocalSystem via a single HTTP request. Defenders should prioritize patching or mitigation to prevent potential disruption and unauthorized access. The vulnerability exists in the Login.aspx admin panel handlers of mJobTime 15.7.3.32, where

Sources and references

Verified primary and authoritative sources

  • CVE-2026-9209 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-9209

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-9209 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-9209

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • mJobTime 15.7.3.32 Unauthenticated SQL Execution RCE via Login.aspx

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/9xxx/CVE-2026-9209.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://www.sprocketsecurity.com/blog/cve-2026-9209-pre-authentication-sql-injection-to-remote-code-execution-in-mjobtime

    Supplemental source - technical-description, exploit

  • Source reference

    Unverified legacy reference

    URL: https://mjobtime.com/

    Supplemental source - product

  • Source reference

    Unverified legacy reference

    URL: https://www.vulncheck.com/advisories/mjobtime-unauthenticated-sql-execution-rce-via-login-aspx

    Supplemental source - third-party-advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.