PatchSiren cyber security CVE debrief
CVE-2026-9209 mJob CVE debrief
A critical vulnerability exists in mJobTime 15.7.3.32, allowing unauthenticated SQL execution via the Login.aspx admin panel. This issue enables attackers to execute arbitrary SQL, invoke xp_cmdshell and xp_read_file, and achieve pre-authentication remote code execution as LocalSystem via a single HTTP request. The vulnerability is confirmed in mJobTime 15.7.3.32 and defenders should assess exposure and prioritize patching or mitigation. The vulnerability exists in the Login.aspx admin panel handlers of mJobTime 15.7.3.32, where the runQueryButton postback and exportSqlQuery_Server PageMethod execute caller-supplied SQL against the Sybase SQL Anywhere database with DBA/sysadmin
- Vendor
- mJob
- Product
- mJobTime
- CVSS
- CRITICAL 9.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Defenders and administrators of mJobTime 15.7.3.32 should assess exposure and prioritize patching or mitigation to prevent potential disruption and unauthorized access. The vulnerability is confirmed in mJobTime 15.7.3.32 and defenders should assess exposure and prioritize patching or mitigation. The issue enables attackers to execute arbitrary SQL, invoke xp_cmdshell and xp_read_file, and achieve pre-authentication remote code execution as LocalSystem via
Why it matters
CVE-2026-9209 is a critical vulnerability in mJobTime 15.7.3.32 that allows unauthenticated SQL execution and remote code execution. Defenders should prioritize patching or mitigation to prevent potential disruption and unauthorized access.
- Potential for pre-authentication remote code execution as LocalSystem
- Unauthenticated SQL execution via exposed endpoints
- Invocation of xp_cmdshell and xp_read_file
- Possible disruption of critical business operations
Technical summary
The vulnerability exists in the Login.aspx admin panel handlers of mJobTime 15.7.3.32, where the runQueryButton postback and exportSqlQuery_Server PageMethod execute caller-supplied SQL against the Sybase SQL Anywhere database with DBA/sysadmin privileges, without server-side authentication. Attackers can submit arbitrary SQL through these exposed endpoints to invoke xp_cmdshell and xp_read_file, achieving pre-authentication remote code execution as LocalSystem via a single HTTP request. The vulnerability is confirmed in mJobTime 15.7.3.32 and defenders should assess exposure and prioritize patching or mitigation.
Defensive priority
High priority for immediate patching or mitigation
Recommended defensive actions
- Immediately patch or update mJobTime to a version beyond 15.7.3.32
- Implement Web Application Firewall (WAF) rules to detect and block suspicious SQL queries
- Conduct thorough inventory checks to identify and mitigate exposure
- Monitor for unusual activity or exploitation attempts
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The vulnerability is confirmed in mJobTime 15.7.3.32. Official sources and references provide details on the unauthenticated SQL execution vulnerability. The issue enables attackers to execute arbitrary SQL, invoke xp_cmdshell and xp_read_file, and achieve pre-authentication remote code execution as LocalSystem via a single HTTP request. Defenders should prioritize patching or mitigation to prevent potential disruption and unauthorized access. The vulnerability exists in the Login.aspx admin panel handlers of mJobTime 15.7.3.32, where
Sources and references
Verified primary and authoritative sources
-
CVE-2026-9209 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-9209
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-9209 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-9209
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
mJobTime 15.7.3.32 Unauthenticated SQL Execution RCE via Login.aspx
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/9xxx/CVE-2026-9209.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://www.sprocketsecurity.com/blog/cve-2026-9209-pre-authentication-sql-injection-to-remote-code-execution-in-mjobtime
Supplemental source - technical-description, exploit
-
Source reference
Unverified legacy reference
URL: https://mjobtime.com/
Supplemental source - product
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/mjobtime-unauthenticated-sql-execution-rce-via-login-aspx
Supplemental source - third-party-advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.