Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 08 Oct 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mjob
Mjob mjobtime |
|
| Vendors & Products |
Mjob
Mjob mjobtime |
Thu, 08 Oct 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 08 Oct 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | mJobTime through build 15.7.3.32 contains an unauthenticated SQL execution vulnerability in the Login.aspx admin panel handlers, where the runQueryButton postback and exportSqlQuery_Server PageMethod execute caller-supplied SQL against the backing Sybase SQL Anywhere database using DBA/sysadmin privileges with no server-side authentication enforced beyond a client-side sessionStorage flag. Attackers can submit arbitrary SQL through these exposed endpoints to invoke xp_cmdshell and xp_read_file, achieving pre-authentication remote code execution as LocalSystem via a single HTTP request. | |
| Title | mJobTime 15.7.3.32 Unauthenticated SQL Execution RCE via Login.aspx | |
| Weaknesses | CWE-250 CWE-306 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-08T17:52:00.960Z
Reserved: 2026-05-21T17:27:06.316Z
Link: CVE-2026-9209
Updated: 2026-10-08T16:00:33.907Z
Status : Received
Published: 2026-10-08T15:17:57.677
Modified: 2026-10-08T18:18:33.757
Link: CVE-2026-9209
No data.
OpenCVE Enrichment
Updated: 2026-10-08T20:00:02Z