CVE-2026-9209
Received Received - Intake

Unauthenticated SQL Injection in mJobTime Admin Panel

Vulnerability report for CVE-2026-9209, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: VulnCheck

Description

mJobTime through build 15.7.3.32 contains an unauthenticated SQL execution vulnerability in the Login.aspx admin panel handlers, where the runQueryButton postback and exportSqlQuery_Server PageMethod execute caller-supplied SQL against the backing Sybase SQL Anywhere database using DBA/sysadmin privileges with no server-side authentication enforced beyond a client-side sessionStorage flag. Attackers can submit arbitrary SQL through these exposed endpoints to invoke xp_cmdshell and xp_read_file, achieving pre-authentication remote code execution as LocalSystem via a single HTTP request.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mJob mJobTime 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
CWE-250 The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a critical unauthenticated SQL execution vulnerability in mJobTime's Login.aspx admin panel. Attackers can send malicious SQL commands through exposed endpoints without authentication. The database runs with DBA/sysadmin privileges, allowing execution of dangerous stored procedures like xp_cmdshell and xp_read_file. This enables pre-authentication remote code execution as LocalSystem via a single HTTP request.

Detection Guidance

Check if mJobTime is running version 15.7.3.32 or earlier. Inspect network traffic for HTTP POST requests to Login.aspx with parameters like runQueryButton or exportSqlQuery_Server. Look for unusual SQL queries or commands like xp_cmdshell or xp_read_file in database logs.

Impact Analysis

An attacker could gain full control over the mJobTime server, execute arbitrary commands, read sensitive files, or install malware. Since the database runs with admin privileges, they could also steal or manipulate all data in the system, including employee records, payroll data, and construction project information.

Compliance Impact

This vulnerability likely violates multiple compliance requirements due to unauthorized data access and potential data breaches. GDPR requires protecting personal data, while HIPAA mandates securing health-related information. The lack of authentication and admin-level database access creates high risk of non-compliance and potential regulatory penalties.

Mitigation Strategies

Restrict network access to the mJobTime web tier using firewalls. Disable the vulnerable handlers (runQueryButton, exportSqlQuery_Server) at the IIS level. Reconfigure the database connection to use a least-privileged account instead of sysadmin.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-9209. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart