CRITICAL
mJob
CVE published 2026-10-08
CVE-2026-9209
A critical vulnerability exists in mJobTime 15.7.3.32, allowing unauthenticated SQL execution via the Login.aspx admin panel. This issue enables attackers to execute arbitrary SQL, invoke xp_cmdshell and xp_read_file, and achieve pre-authentication remote code execution as LocalSystem via a single HTTP request. The vulnerability is confirmed in mJobTime 15.7.3.32 and defenders should assess exposure and p [truncated]