CRITICAL
9.8 CVE-2026-9209 Published 8 Oct 2026
mJobTime Admin Panel SQL Injection Leads to Pre-Auth RCE
Worried this affects your website?
mJobTime through build 15.7.3.32 contains an unauthenticated SQL execution vulnerability in the Login.aspx admin panel handlers.
The runQueryButton postback and exportSqlQuery_Server PageMethod execute caller-supplied SQL against the backing Sybase SQL Anywhere database using DBA/sysadmin privileges. No server-side authentication is enforced beyond a client-side sessionStorage flag.
- Attackers can submit arbitrary SQL through these exposed endpoints.
- They can invoke xp_cmdshell and xp_read_file.
- This achieves pre-authentication remote code execution as LocalSystem via a single HTTP request.
Reference: CVE-2026-9209 on NVD
← Back to Security News