CRITICAL 9.8 CVE-2026-9209 Published 8 Oct 2026

mJobTime Admin Panel SQL Injection Leads to Pre-Auth RCE

Worried this affects your website?

mJobTime through build 15.7.3.32 contains an unauthenticated SQL execution vulnerability in the Login.aspx admin panel handlers.

The runQueryButton postback and exportSqlQuery_Server PageMethod execute caller-supplied SQL against the backing Sybase SQL Anywhere database using DBA/sysadmin privileges. No server-side authentication is enforced beyond a client-side sessionStorage flag.

  • Attackers can submit arbitrary SQL through these exposed endpoints.
  • They can invoke xp_cmdshell and xp_read_file.
  • This achieves pre-authentication remote code execution as LocalSystem via a single HTTP request.

Reference: CVE-2026-9209 on NVD

← Back to Security News